|
210111
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_studio_photo
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the …
|
-
|
CVE-2020-15629
|
2024-11-21 14:05 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210112
|
6.7 |
MEDIUM
Local
|
hp
|
elite_x2_1012_g1_firmware elite_x2_1012_g2_firmware elitebook_1030_g1_firmware elitebook_1040_g4_firmware elitebook_folio_1040_g3_firmware elitebook_folio_g1_firmware elitebook_revo…
|
The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-15596
|
2024-11-21 14:05 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210113
|
5.4 |
MEDIUM
Network
|
soplanning
|
soplanning
|
SOPlanning 1.46.01 allows persistent XSS via the Project Name, Statutes Comment, Places Comment, or Resources Comment field.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15597
|
2024-11-21 14:05 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210114
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the user downloading an unintended file. This vulnerability affects Firefox for iOS…
|
NVD-CWE-Other
|
CVE-2020-15662
|
2024-11-21 14:05 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210115
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain. This vulnerability affects Firefox for iO…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-15661
|
2024-11-21 14:05 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210116
|
8.8 |
HIGH
Network
|
mozilla opensuse canonical
|
firefox firefox_esr thunderbird leap ubuntu_linux
|
Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence of memory corruption and we presume that with enoug…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-15659
|
2024-11-21 14:05 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210117
|
6.5 |
MEDIUM
Network
|
mozilla canonical
|
thunderbird firefox_esr firefox ubuntu_linux
|
The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file typ…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2020-15658
|
2024-11-21 14:05 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210118
|
7.8 |
HIGH
Local
|
mozilla
|
firefox firefox_esr thunderbird
|
Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. *Note: Thi…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-15657
|
2024-11-21 14:05 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210119
|
8.8 |
HIGH
Network
|
mozilla opensuse canonical
|
thunderbird firefox_esr firefox leap ubuntu_linux
|
JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions in the code, resulting in this bug rated at only …
|
CWE-843
Type Confusion
|
CVE-2020-15656
|
2024-11-21 14:05 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210120
|
6.5 |
MEDIUM
Network
|
mozilla opensuse canonical
|
thunderbird firefox_esr firefox leap ubuntu_linux
|
A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-origin information. This vulnerability affe…
|
NVD-CWE-noinfo
|
CVE-2020-15655
|
2024-11-21 14:05 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|