|
198241
|
9.8 |
CRITICAL
Network
|
rubyonrails debian opensuse
|
rails debian_linux leap
|
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore pote…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-8165
|
2024-11-21 14:38 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198242
|
7.5 |
HIGH
Network
|
rack_project debian canonical
|
rack debian_linux ubuntu_linux
|
A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie pr…
|
CWE-20
Improper Input Validation
|
CVE-2020-8184
|
2024-11-21 14:38 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198243
|
7.5 |
HIGH
Network
|
rubyonrails debian opensuse
|
rails debian_linux leap backports_sle
|
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-8164
|
2024-11-21 14:38 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198244
|
7.5 |
HIGH
Network
|
rubyonrails debian
|
rails debian_linux
|
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be m…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-8162
|
2024-11-21 14:38 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198245
|
5.7 |
MEDIUM
Network
|
openmicroscopy
|
omero.web
|
OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, …
|
CWE-200
Information Exposure
|
CVE-2020-7932
|
2024-11-21 14:38 |
2020-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198246
|
6.5 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.3 allows XXE attacks.
|
CWE-611
XXE
|
CVE-2020-8541
|
2024-11-21 14:38 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198247
|
6.7 |
MEDIUM
Local
|
synaptics
|
smart_audio_uwp
|
An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCHU audio drivers on Lenovo platforms that could allow an ad…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2020-8337
|
2024-11-21 14:38 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198248
|
6.8 |
MEDIUM
Physics
|
lenovo
|
thinkpad_e14_firmware thinkpad_e15_firmware thinkpad_r14_firmware thinkpad_s3_gen_2_firmware thinkpad_e490s_firmware thinkpad_s3_firmware thinkpad_e490_firmware thinkpad_e590_fir…
|
Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash.
|
NVD-CWE-noinfo
|
CVE-2020-8336
|
2024-11-21 14:38 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198249
|
6.8 |
MEDIUM
Physics
|
lenovo
|
thinkpad_t495s_firmware thinkpad_x395_firmware thinkpad_t495_firmware thinkpad_a485_firmware thinkpad_a285_firmware thinkpad_a475_firmware thinkpad_a275_firmware
|
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized access.
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2020-8334
|
2024-11-21 14:38 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198250
|
6.7 |
MEDIUM
Local
|
lenovo
|
330-14ast_firmware 330-15ast_firmware 330-17ast_firmware 340c-15api_firmware 340c-15ast_firmware 720s_touch-15ikb_firmware 720s-15ikb_firmware 730s-13iwl_firmware c640-iml_fir…
|
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.
|
NVD-CWE-noinfo
|
CVE-2020-8323
|
2024-11-21 14:38 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|