|
197291
|
5.5 |
MEDIUM
Local
|
apple
|
mac_os_x
|
A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to read arbitrary files.
|
NVD-CWE-noinfo
|
CVE-2020-3889
|
2024-11-21 14:31 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197292
|
4.3 |
MEDIUM
Network
|
apple
|
iphone_os ipad_os
|
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4. A maliciously crafted page may interfere with other web contexts.
|
NVD-CWE-noinfo
|
CVE-2020-3888
|
2024-11-21 14:31 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197293
|
4.3 |
MEDIUM
Network
|
apple
|
itunes iphone_os tvos safari ipad_os icloud
|
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Wind…
|
NVD-CWE-Other
|
CVE-2020-3887
|
2024-11-21 14:31 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197294
|
4.3 |
MEDIUM
Network
|
apple
|
itunes iphone_os tvos safari ipad_os icloud
|
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Wind…
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2020-3885
|
2024-11-21 14:31 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197295
|
6.1 |
MEDIUM
Network
|
apple
|
mac_os_x
|
An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbitrary javascript code execution.
|
CWE-20 CWE-74
Improper Input Validation Injection
|
CVE-2020-3884
|
2024-11-21 14:31 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197296
|
8.8 |
HIGH
Network
|
apple
|
iphone_os tvos watchos ipad_os mac_os_x
|
This issue was addressed with improved checks. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. An application may be able to use arbitrary entitlement…
|
NVD-CWE-noinfo
|
CVE-2020-3883
|
2024-11-21 14:31 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197297
|
5.5 |
MEDIUM
Local
|
apple
|
mac_os_x
|
A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to view sensitive user information.
|
NVD-CWE-noinfo
|
CVE-2020-3881
|
2024-11-21 14:31 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197298
|
9.8 |
CRITICAL
Network
|
unisoon
|
ultralog_express_firmware
|
UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.
|
CWE-89
SQL Injection
|
CVE-2020-3936
|
2024-11-21 14:31 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197299
|
7.5 |
HIGH
Network
|
unisoon
|
ultralog_express_firmware
|
UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts information through a specific page.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-3921
|
2024-11-21 14:31 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197300
|
8.1 |
HIGH
Network
|
unisoon
|
ultralog_express_firmware
|
UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access the privileged page to manage accounts through speci…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-3920
|
2024-11-21 14:31 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|