|
197701
|
5.5 |
MEDIUM
Local
|
puppet
|
continuous_delivery
|
Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is resolved in Continuous …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-7945
|
2024-11-21 14:38 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197702
|
9.3 |
CRITICAL
Local
|
suse
|
salt-netapi-client
|
A Improper Access Control vulnerability in the configuration of salt of SUSE Linux Enterprise Module for SUSE Manager Server 4.1, SUSE Manager Proxy 4.0, SUSE Manager Retail Branch Server 4.0, SUSE M…
|
-
|
CVE-2020-8028
|
2024-11-21 14:38 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197703
|
5.5 |
MEDIUM
Local
|
lenovo
|
system_interface_foundation
|
A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 that could allow configuration files to be written t…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-8346
|
2024-11-21 14:38 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197704
|
7.0 |
HIGH
Local
|
lenovo
|
system_update
|
A race condition vulnerability was reported in Lenovo System Update prior to version 5.07.0106 that could allow escalation of privilege.
|
CWE-362
Race Condition
|
CVE-2020-8342
|
2024-11-21 14:38 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197705
|
6.1 |
MEDIUM
Network
|
lenovo
|
integrated_management_module_2
|
A cross-site scripting (XSS) vulnerability was discovered in the legacy IBM and Lenovo System x IMM2 (Integrated Management Module 2), prior to version 5.60, embedded Baseboard Management Controller …
|
CWE-79
Cross-site Scripting
|
CVE-2020-8340
|
2024-11-21 14:38 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197706
|
6.1 |
MEDIUM
Network
|
ibm
|
bladecenter_advanced_management_module_firmware
|
A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior to version 3.68n [BPET68N]. This vulnerability co…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8339
|
2024-11-21 14:38 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197707
|
2.4 |
LOW
Physics
|
lenovo
|
thinkpad_t490_\(20nx\)_firmware thinkpad_t490_\(20qx\)_firmware thinkpad_t490_\(20rx\)_firmware thinkpad_t490s_\(20nx\)_firmware thinkpad_t495_drift_firmware thinkpad_t590_\(20nx\)_fir…
|
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Re…
|
NVD-CWE-noinfo
|
CVE-2020-8341
|
2024-11-21 14:38 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197708
|
6.8 |
MEDIUM
Physics
|
lenovo
|
thinkpad_a275_firmware thinkpad_a285_firmware thinkpad_a475_firmware thinkpad_a485_firmware thinkpad_t495_drift_firmware thinkpad_t495s_jazz_firmware thinkpad_x1_carbon_\(20bx\)_fir…
|
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS ve…
|
NVD-CWE-noinfo
|
CVE-2020-8335
|
2024-11-21 14:38 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197709
|
7.8 |
HIGH
Local
|
opensuse
|
openldap2
|
A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise …
|
-
|
CVE-2020-8023
|
2024-11-21 14:38 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197710
|
7.8 |
HIGH
Local
|
bitdefender
|
endpoint_security endpoint_security_tools
|
An improper authentication vulnerability in Bitdefender Endpoint Security Tools for Windows and Bitdefender Endpoint Security SDK allows an unprivileged local attacker to escalate privileges or tampe…
|
CWE-287
Improper Authentication
|
CVE-2020-8097
|
2024-11-21 14:38 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|