|
197791
|
6.7 |
MEDIUM
Local
|
lenovo
|
130-14ast_firmware 130-14ikb_firmware 130-15ast_firmware 130-15ikb_firmware 320c-15ikb_firmware 330-14igm_firmware 330-14ikb_firmware 330-14ikbr_firmware 330-15arr_firmware
|
A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.
|
NVD-CWE-noinfo
|
CVE-2020-8321
|
2024-11-21 14:38 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197792
|
6.8 |
MEDIUM
Physics
|
lenovo
|
thinkpad_11e_yoga_gen_6_firmware thinkpad_11e_firmware thinkpad_yoga_11e_3rd_gen_firmware thinkpad_yoga_11e_4th_gen_firmware thinkpad_yoga_11e_5th_gen_firmware thinkpad_13_2nd_gen_firm…
|
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
|
CWE-269
Improper Privilege Management
|
CVE-2020-8320
|
2024-11-21 14:38 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197793
|
9.9 |
CRITICAL
Network
|
nextcloud
|
talk
|
A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator.
|
CWE-94
Code Injection
|
CVE-2020-8180
|
2024-11-21 14:38 |
2020-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197794
|
7.4 |
HIGH
Network
|
nodejs oracle
|
node.js graalvm banking_extensibility_workbench mysql_cluster blockchain_platform
|
TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-8172
|
2024-11-21 14:38 |
2020-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197795
|
7.1 |
HIGH
Local
|
bitdefender
|
antivirus_2020
|
A vulnerability in the improper handling of symbolic links in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, and restore it to a privileged location. This…
|
CWE-59
Link Following
|
CVE-2020-8103
|
2024-11-21 14:38 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197796
|
5.5 |
MEDIUM
Local
|
abb
|
device_library_wizard
|
Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauthenticated low privilege user to read file that contains confidential data
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2020-8482
|
2024-11-21 14:38 |
2020-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197797
|
7.5 |
HIGH
Network
|
lenovo
|
lj4010dn_firmware lj6700dn_firmware m8960dnf_firmware
|
A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggered by a remote user sending a crafted packet to the device, p…
|
NVD-CWE-noinfo
|
CVE-2020-8330
|
2024-11-21 14:38 |
2020-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197798
|
7.5 |
HIGH
Network
|
lenovo
|
lj4010dn_firmware lj6700dn_firmware m8960dnf_firmware
|
A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggered by a remote user sending a crafted packet to the device, c…
|
NVD-CWE-noinfo
|
CVE-2020-8329
|
2024-11-21 14:38 |
2020-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197799
|
9.8 |
CRITICAL
Network
|
ui
|
airos
|
We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the…
|
CWE-78
OS Command
|
CVE-2020-8171
|
2024-11-21 14:38 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197800
|
6.1 |
MEDIUM
Network
|
ui
|
airos
|
We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8170
|
2024-11-21 14:38 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|