|
210211
|
3.3 |
LOW
Local
|
pulseaudio canonical
|
pulseaudio ubuntu_linux
|
An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulse…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-11931
|
2024-11-21 13:58 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210212
|
2.3 |
LOW
Local
|
canonical
|
subiquity
|
It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-11932
|
2024-11-21 13:58 |
2020-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210213
|
7.8 |
HIGH
Local
|
libemf_project opensuse fedoraproject
|
libemf leap fedora
|
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.
|
CWE-416
Use After Free
|
CVE-2020-11866
|
2024-11-21 13:58 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210214
|
7.8 |
HIGH
Local
|
libemf_project opensuse fedoraproject
|
libemf leap fedora
|
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-11865
|
2024-11-21 13:58 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210215
|
5.5 |
MEDIUM
Local
|
libemf_project opensuse fedoraproject
|
libemf leap fedora
|
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 2 of 2).
|
NVD-CWE-noinfo
|
CVE-2020-11864
|
2024-11-21 13:58 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210216
|
5.5 |
MEDIUM
Local
|
libemf_project opensuse fedoraproject
|
libemf leap fedora
|
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 1 of 2).
|
NVD-CWE-noinfo
|
CVE-2020-11863
|
2024-11-21 13:58 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210217
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_datasecurity_plus manageengine_adaudit_plus
|
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and e…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2020-11532
|
2024-11-21 13:58 |
2020-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210218
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_adaudit_plus manageengine_datasecurity_plus
|
The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the database schema name when handling a DR-SCHEMA-SYNC request. This allows an authent…
|
CWE-22
Path Traversal
|
CVE-2020-11531
|
2024-11-21 13:58 |
2020-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210219
|
9.8 |
CRITICAL
Network
|
idangero
|
chop_slider
|
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter supplied to get_script/index.php, and allows an attacker t…
|
CWE-89
SQL Injection
|
CVE-2020-11530
|
2024-11-21 13:58 |
2020-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210220
|
5.5 |
MEDIUM
Local
|
techsmith
|
snagit
|
In TechSmith SnagIt 11.2.1 through 20.0.3, an XML External Entity (XXE) injection issue exists that would allow a local attacker to exfiltrate data under the local Administrator account.
|
CWE-611
XXE
|
CVE-2020-11541
|
2024-11-21 13:58 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|