|
196011
|
7.0 |
HIGH
Local
|
lenovo
|
system_update
|
A race condition vulnerability was reported in Lenovo System Update prior to version 5.07.0106 that could allow escalation of privilege.
|
CWE-362
Race Condition
|
CVE-2020-8342
|
2024-11-21 14:38 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196012
|
6.1 |
MEDIUM
Network
|
lenovo
|
integrated_management_module_2
|
A cross-site scripting (XSS) vulnerability was discovered in the legacy IBM and Lenovo System x IMM2 (Integrated Management Module 2), prior to version 5.60, embedded Baseboard Management Controller …
|
CWE-79
Cross-site Scripting
|
CVE-2020-8340
|
2024-11-21 14:38 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196013
|
6.1 |
MEDIUM
Network
|
ibm
|
bladecenter_advanced_management_module_firmware
|
A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior to version 3.68n [BPET68N]. This vulnerability co…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8339
|
2024-11-21 14:38 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196014
|
2.4 |
LOW
Physics
|
lenovo
|
thinkpad_t490_\(20nx\)_firmware thinkpad_t490_\(20qx\)_firmware thinkpad_t490_\(20rx\)_firmware thinkpad_t490s_\(20nx\)_firmware thinkpad_t495_drift_firmware thinkpad_t590_\(20nx\)_fir…
|
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Re…
|
NVD-CWE-noinfo
|
CVE-2020-8341
|
2024-11-21 14:38 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196015
|
6.8 |
MEDIUM
Physics
|
lenovo
|
thinkpad_a275_firmware thinkpad_a285_firmware thinkpad_a475_firmware thinkpad_a485_firmware thinkpad_t495_drift_firmware thinkpad_t495s_jazz_firmware thinkpad_x1_carbon_\(20bx\)_fir…
|
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS ve…
|
NVD-CWE-noinfo
|
CVE-2020-8335
|
2024-11-21 14:38 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196016
|
7.8 |
HIGH
Local
|
opensuse
|
openldap2
|
A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise …
|
-
|
CVE-2020-8023
|
2024-11-21 14:38 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196017
|
7.8 |
HIGH
Local
|
bitdefender
|
endpoint_security endpoint_security_tools
|
An improper authentication vulnerability in Bitdefender Endpoint Security Tools for Windows and Bitdefender Endpoint Security SDK allows an unprivileged local attacker to escalate privileges or tampe…
|
CWE-287
Improper Authentication
|
CVE-2020-8097
|
2024-11-21 14:38 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196018
|
6.5 |
MEDIUM
Network
|
bufferlist_project debian
|
bufferlist debian_linux
|
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can becom…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-8244
|
2024-11-21 14:38 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196019
|
9.8 |
CRITICAL
Network
|
ui
|
edgemax_firmware
|
A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be guessed, enabling the attacker to obtain high privileges and…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-8234
|
2024-11-21 14:38 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196020
|
6.8 |
MEDIUM
Network
|
nextcloud
|
desktop
|
Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.
|
CWE-22
Path Traversal
|
CVE-2020-8227
|
2024-11-21 14:38 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|