|
197231
|
7.8 |
HIGH
Local
|
intel
|
thunderbolt_non-dch_driver
|
Improper permissions in the installer for the Intel(R) Thunderbolt(TM) non-DCH driver, all versions, for Windows may allow an authenticated user to potentially enable escalation of privilege via loca…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-8741
|
2024-11-21 14:39 |
2021-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197232
|
4.1 |
MEDIUM
Network
|
kubernetes
|
kubernetes
|
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver re…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2020-8561
|
2024-11-21 14:39 |
2021-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197233
|
7.5 |
HIGH
Network
|
iportalis
|
iportalis_control_portal
|
An issue was discovered in iPortalis iCS 7.1.13.0. An attacker can gain privileges by intercepting a request and changing UserRoleKey=COMPANY_ADMIN to UserRoleKey=DOMAIN_ADMIN (to achieve Domain Admi…
|
CWE-20
Improper Input Validation
|
CVE-2020-9002
|
2024-11-21 14:39 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197234
|
7.5 |
HIGH
Network
|
iportalis
|
iportalis_control_portal
|
An issue was discovered in iPortalis iCS 7.1.13.0. Attackers can send a sequence of requests to rapidly cause .NET Input Validation errors. This increases the size of the log file on the remote serve…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-9000
|
2024-11-21 14:39 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197235
|
7.3 |
HIGH
Local
|
intel
|
processor_diagnostic_tool
|
Uncontrolled search path element in the Intel(R) Processor Diagnostic Tool before version 4.1.5.37 may allow an authenticated user to potentially enable escalation of privilege via local access.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-8702
|
2024-11-21 14:39 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197236
|
6.7 |
MEDIUM
Local
|
intel netapp
|
bios cloud_backup hci_storage_node_bios solidfire_bios hci_compute_node_bios aff_bios fas_bios e-series_bios
|
Improper input validation in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
|
CWE-20
Improper Input Validation
|
CVE-2020-8700
|
2024-11-21 14:39 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197237
|
6.4 |
MEDIUM
Local
|
intel siemens
|
local_manageability_service simatic_field_pg_m5_firmware simatic_field_pg_m6_firmware simatic_ipc427e_firmware simatic_ipc477e_firmware simatic_ipc477e_pro_firmware simatic_ipc527g_…
|
Race condition in a subsystem in the Intel(R) LMS versions before 2039.1.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.
|
CWE-362
Race Condition
|
CVE-2020-8704
|
2024-11-21 14:39 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197238
|
6.7 |
MEDIUM
Local
|
intel netapp siemens
|
converged_security_and_manageability_engine cloud_backup simatic_field_pg_m6_firmware simatic_field_pg_m5_firmware simatic_ipc427e_firmware simatic_ipc477e_firmware simatic_ipc477e_…
|
Improper buffer restrictions in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32 and 15.0.22 may allow a privileged user to p…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-8703
|
2024-11-21 14:39 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197239
|
6.4 |
MEDIUM
Local
|
intel siemens netapp
|
bios simatic_field_pg_m6_firmware simatic_ipc427e_firmware simatic_ipc477e_firmware simatic_ipc477e_pro_firmware simatic_ipc527g_firmware simatic_ipc547g_firmware simatic_ipc627e…
|
Race condition in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
|
CWE-362
Race Condition
|
CVE-2020-8670
|
2024-11-21 14:39 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197240
|
4.3 |
MEDIUM
Network
|
google
|
rendertron
|
Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-8902
|
2024-11-21 14:39 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|