|
210271
|
7.8 |
HIGH
Local
|
trendmicro
|
apex_one
|
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary code on affected products. User interaction is required to exploit this vulnerab…
|
CWE-415
Double Free
|
CVE-2020-25773
|
2024-11-21 14:18 |
2020-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210272
|
5.5 |
MEDIUM
Local
|
trendmicro
|
apex_one
|
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installation…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-25772
|
2024-11-21 14:18 |
2020-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210273
|
5.5 |
MEDIUM
Local
|
trendmicro
|
apex_one
|
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installation…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-25771
|
2024-11-21 14:18 |
2020-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210274
|
5.5 |
MEDIUM
Local
|
trendmicro
|
apex_one
|
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installation…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-25770
|
2024-11-21 14:18 |
2020-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210275
|
7.5 |
HIGH
Network
|
mediawiki fedoraproject
|
mediawiki fedora
|
An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. Handling of actor ID does not necessarily use the correct database or correct wiki.
|
CWE-863
Incorrect Authorization
|
CVE-2020-25869
|
2024-11-21 14:18 |
2020-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210276
|
7.5 |
HIGH
Network
|
mediawiki fedoraproject
|
mediawiki fedora
|
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limit…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-25827
|
2024-11-21 14:18 |
2020-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210277
|
6.1 |
MEDIUM
Network
|
mediawiki fedoraproject
|
mediawiki fedora
|
An issue was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. The non-jqueryMsg version of mw.message().parse() doesn't escape HTML. This affects both message contents …
|
CWE-79
Cross-site Scripting
|
CVE-2020-25828
|
2024-11-21 14:18 |
2020-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210278
|
6.1 |
MEDIUM
Network
|
mediawiki fedoraproject
|
mediawiki fedora
|
An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDesc is insecurely using message text to build options names for an HTML multi-select field. The rele…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25815
|
2024-11-21 14:18 |
2020-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210279
|
6.1 |
MEDIUM
Network
|
mediawiki fedoraproject
|
mediawiki fedora
|
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, XSS related to jQuery can occur. The attacker creates a message with [javascript:payload xss] and turns it into a jQuery object wi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25814
|
2024-11-21 14:18 |
2020-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210280
|
5.3 |
MEDIUM
Network
|
mediawiki fedoraproject
|
mediawiki fedora
|
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:UserRights exposes the existence of hidden users.
|
NVD-CWE-noinfo
|
CVE-2020-25813
|
2024-11-21 14:18 |
2020-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|