|
196071
|
4.8 |
MEDIUM
Network
|
kronos
|
web_time_and_attendance
|
A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fields (Login Message, Banner Message, and Password Instruction…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8493
|
2024-11-21 14:38 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196072
|
5.5 |
MEDIUM
Local
|
bitdefender
|
total_security_2020
|
A vulnerability in the improper handling of junctions before deletion in Bitdefender Total Security 2020 can allow an attacker to to trigger a denial of service on the affected device.
|
CWE-20
Improper Input Validation
|
CVE-2020-8095
|
2024-11-21 14:38 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196073
|
6.5 |
MEDIUM
Network
|
python opensuse canonical fedoraproject debian
|
python leap ubuntu_linux fedora debian_linux
|
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks agains…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-8492
|
2024-11-21 14:38 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196074
|
7.8 |
HIGH
Local
|
bitdefender
|
antivirus
|
A vulnerability in the AntivirusforMac binary as used in Bitdefender Antivirus for Mac allows an attacker to inject a library using DYLD environment variable to cause third-party code execution
|
CWE-74
Injection
|
CVE-2020-8093
|
2024-11-21 14:38 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196075
|
5.5 |
MEDIUM
Local
|
bitdefender
|
antivirus
|
A privilege escalation vulnerability in BDLDaemon as used in Bitdefender Antivirus for Mac allows a local attacker to obtain authentication tokens for requests submitted to the Bitdefender Cloud. Thi…
|
CWE-269
Improper Privilege Management
|
CVE-2020-8092
|
2024-11-21 14:38 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196076
|
5.5 |
MEDIUM
Local
|
ossec
|
ossec
|
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a denial of service (NULL pointer dereference) via crafted messages written direc…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-8448
|
2024-11-21 14:38 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196077
|
9.8 |
CRITICAL
Network
|
ossec
|
ossec
|
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during processing of syscheck formatted msgs (received from auth…
|
CWE-416
Use After Free
|
CVE-2020-8447
|
2024-11-21 14:38 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196078
|
5.5 |
MEDIUM
Local
|
ossec
|
ossec
|
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to path traversal (with write access) via crafted syscheck messages written directly…
|
CWE-22
Path Traversal
|
CVE-2020-8446
|
2024-11-21 14:38 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196079
|
9.8 |
CRITICAL
Network
|
ossec
|
ossec
|
In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from processed log messages. In many cases, those charact…
|
CWE-20
Improper Input Validation
|
CVE-2020-8445
|
2024-11-21 14:38 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196080
|
9.8 |
CRITICAL
Network
|
ossec
|
ossec
|
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during processing of ossec-alert formatted msgs (received from a…
|
CWE-416
Use After Free
|
CVE-2020-8444
|
2024-11-21 14:38 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|