|
196061
|
5.5 |
MEDIUM
Local
|
google
|
asylo
|
An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allows an attacker to make a host call to UntrustedCall. UntrustedCall failed to validate the buffer range within sgx_params …
|
CWE-125
Out-of-bounds Read
|
CVE-2020-8936
|
2024-11-21 14:39 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196062
|
7.8 |
HIGH
Local
|
google
|
asylo
|
An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allow an attacker to make an Ecall_restore function call to reallocate untrusted code and overwrite sections of the Enclave m…
|
CWE-119 CWE-787
Incorrect Access of Indexable Resource ('Range Error') Out-of-bounds Write
|
CVE-2020-8935
|
2024-11-21 14:39 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196063
|
3.3 |
LOW
Local
|
google quarkus oracle netapp
|
guava quarkus peoplesoft_enterprise_peopletools data_integrator weblogic_server nosql_database commerce_guided_search communications_cloud_native_core_network_slice_selection_fun…
|
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API c…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-8908
|
2024-11-21 14:39 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196064
|
3.5 |
LOW
Adjacent
|
google
|
gerrit
|
An information leak vulnerability exists in Gerrit versions prior to 2.14.22, 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where an overoptimization with the FilteredRepository wrapper skips the verificat…
|
NVD-CWE-Other
|
CVE-2020-8920
|
2024-11-21 14:39 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196065
|
3.5 |
LOW
Adjacent
|
google
|
gerrit
|
An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the defau…
|
CWE-863
Incorrect Authorization
|
CVE-2020-8919
|
2024-11-21 14:39 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196066
|
5.5 |
MEDIUM
Local
|
kubernetes
|
kubernetes
|
In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during p…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-8566
|
2024-11-21 14:39 |
2020-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196067
|
5.5 |
MEDIUM
Local
|
kubernetes
|
kubernetes
|
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. Thi…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-8565
|
2024-11-21 14:39 |
2020-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196068
|
5.5 |
MEDIUM
Local
|
kubernetes
|
kubernetes
|
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secret…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-8564
|
2024-11-21 14:39 |
2020-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196069
|
5.5 |
MEDIUM
Local
|
kubernetes
|
kubernetes
|
In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This affects < v1.19.…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-8563
|
2024-11-21 14:39 |
2020-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196070
|
5.3 |
MEDIUM
Adjacent
|
johnsoncontrols
|
c-cure_web victor_web
|
A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated attacker on the network to create and sign their own J…
|
CWE-287
Improper Authentication
|
CVE-2020-9049
|
2024-11-21 14:39 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|