|
209591
|
7.4 |
HIGH
Network
|
hibernate debian quarkus oracle
|
hibernate_orm debian_linux quarkus retail_customer_management_and_segmentation_foundation communications_cloud_native_core_console
|
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is use…
|
-
|
CVE-2020-25638
|
2024-11-21 14:18 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209592
|
3.2 |
LOW
Local
|
qemu debian
|
qemu debian_linux
|
A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged us…
|
-
|
CVE-2020-25723
|
2024-11-21 14:18 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209593
|
5.5 |
MEDIUM
Local
|
linux debian starwindsoftware
|
linux_kernel debian_linux starwind_san_\&_nas command_center starwind_virtual_san starwind_hyperconverged_appliance
|
A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER. A local user could use this flaw to starve the resources causing denia…
|
-
|
CVE-2020-25704
|
2024-11-21 14:18 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209594
|
4.1 |
MEDIUM
Local
|
linux redhat debian starwindsoftware
|
linux_kernel enterprise_linux debian_linux starwind_virtual_san
|
A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access …
|
-
|
CVE-2020-25656
|
2024-11-21 14:18 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209595
|
9.8 |
CRITICAL
Network
|
ucms_project
|
ucms
|
File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-25537
|
2024-11-21 14:18 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209596
|
5.0 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-25624
|
2024-11-21 14:18 |
2020-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209597
|
7.5 |
HIGH
Network
|
libvncserver_project redhat debian
|
libvncserver enterprise_linux debian_linux
|
A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a fl…
|
CWE-369
Divide By Zero
|
CVE-2020-25708
|
2024-11-21 14:18 |
2020-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209598
|
5.5 |
MEDIUM
Local
|
cyberark
|
endpoint_privilege_manager
|
CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a process that normally has credential access, such as …
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-25738
|
2024-11-21 14:18 |
2020-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209599
|
6.3 |
MEDIUM
Local
|
spice-space debian fedoraproject
|
spice-vdagent debian_linux fedora
|
A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice…
|
CWE-362
Race Condition
|
CVE-2020-25653
|
2024-11-21 14:18 |
2020-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209600
|
5.5 |
MEDIUM
Local
|
spice-space debian fedoraproject
|
spice-vdagent debian_linux fedora
|
A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket in `/run/spice-vdagentd/spice-vdagent-sock`. Any …
|
-
|
CVE-2020-25652
|
2024-11-21 14:18 |
2020-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|