|
210851
|
6.0 |
MEDIUM
Local
|
tuxfamily fedoraproject canonical
|
chrony fedora ubuntu_linux
|
A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when…
|
CWE-59
Link Following
|
CVE-2020-14367
|
2024-11-21 14:03 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210852
|
7.3 |
HIGH
Local
|
postgresql debian opensuse canonical
|
postgresql debian_linux leap ubuntu_linux
|
It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into exe…
|
CWE-426
Untrusted Search Path
|
CVE-2020-14350
|
2024-11-21 14:03 |
2020-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210853
|
7.1 |
HIGH
Network
|
postgresql opensuse
|
postgresql leap
|
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in …
|
CWE-89 CWE-427
SQL Injection Uncontrolled Search Path Element
|
CVE-2020-14349
|
2024-11-21 14:03 |
2020-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210854
|
5.3 |
MEDIUM
Network
|
philips
|
dreammapper
|
Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance to a potential attacker.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-14518
|
2024-11-21 14:03 |
2020-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210855
|
7.8 |
HIGH
Local
|
linux redhat opensuse debian canonical netapp
|
linux_kernel enterprise_linux leap debian_linux ubuntu_linux cloud_backup solidfire hci_management_node active_iq_unified_manager solidfire_baseboard_management_controller_…
|
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or e…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-14356
|
2024-11-21 14:03 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210856
|
6.1 |
MEDIUM
Network
|
ovirt
|
ovirt-engine
|
A flaw was found in Ovirt Engine's web interface in ovirt 4.4 and earlier, where it did not filter user-controllable parameters completely, resulting in a reflected cross-site scripting attack. This …
|
-
|
CVE-2020-14333
|
2024-11-21 14:03 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210857
|
4.3 |
MEDIUM
Adjacent
|
tridium
|
niagara_enterprise_security niagara
|
A timeout during a TLS handshake can result in the connection failing to terminate. This can result in a Niagara thread hanging and requires a manual restart of Niagara (Versions 4.6.96.28, 4.7.109.2…
|
NVD-CWE-Other
|
CVE-2020-14483
|
2024-11-21 14:03 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210858
|
9.1 |
CRITICAL
Network
|
redhat
|
cloudforms_management_engine
|
A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerability can be exploited by authenticated attacker whi…
|
CWE-78
OS Command
|
CVE-2020-14324
|
2024-11-21 14:03 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210859
|
9.1 |
CRITICAL
Network
|
redhat
|
cloudforms
|
Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious attacker to create existent and non-existent role-based access control user, with…
|
NVD-CWE-noinfo
|
CVE-2020-14325
|
2024-11-21 14:03 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210860
|
5.5 |
MEDIUM
Local
|
x.org debian canonical
|
xorg-server debian_linux ubuntu_linux
|
A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could r…
|
-
|
CVE-2020-14347
|
2024-11-21 14:03 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|