|
208231
|
5.5 |
MEDIUM
Local
|
midnightbsd freebsd
|
midnightbsd freebsd
|
A memory corruption vulnerability was found in the kernel function kern_getfsstat in MidnightBSD before 1.2.7 and 1.3 through 2020-08-19, and FreeBSD through 11.4, that allows an attacker to trigger …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-24863
|
2024-11-21 14:16 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208232
|
8.8 |
HIGH
Network
|
php-fusion
|
php-fusion
|
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).
|
NVD-CWE-noinfo
|
CVE-2020-24949
|
2024-11-21 14:16 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208233
|
7.8 |
HIGH
Local
|
kaspersky
|
security_center_web_console security_center
|
Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijacking attack that allowed an attacker to elevate privi…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-25045
|
2024-11-21 14:16 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208234
|
7.1 |
HIGH
Local
|
kaspersky
|
virus_removal_tool
|
Kaspersky Virus Removal Tool (KVRT) prior to 15.0.23.0 was vulnerable to arbitrary file corruption that could provide an attacker with the opportunity to eliminate content of any file in the system.
|
NVD-CWE-noinfo
|
CVE-2020-25044
|
2024-11-21 14:16 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208235
|
7.1 |
HIGH
Local
|
kaspersky
|
vpn_secure_connection
|
The installer of Kaspersky VPN Secure Connection prior to 5.0 was vulnerable to arbitrary file deletion that could allow an attacker to delete any file in the system.
|
NVD-CWE-noinfo
|
CVE-2020-25043
|
2024-11-21 14:16 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208236
|
4.3 |
MEDIUM
Network
|
derhansen
|
event_management_and_registration
|
The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows Information Disclosure (participant data, and event data via email) because of Br…
|
NVD-CWE-noinfo
|
CVE-2020-25026
|
2024-11-21 14:16 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208237
|
4.3 |
MEDIUM
Network
|
localization_manager_project
|
localization_manager
|
The l10nmgr (aka Localization Manager) extension before 7.4.0, 8.x before 8.7.0, and 9.x before 9.2.0 for TYPO3 allows Information Disclosure (translatable fields).
|
CWE-863
Incorrect Authorization
|
CVE-2020-25025
|
2024-11-21 14:16 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208238
|
7.8 |
HIGH
Local
|
superantispyware
|
professional_x
|
SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via…
|
CWE-59
Link Following
|
CVE-2020-24955
|
2024-11-21 14:16 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208239
|
5.5 |
MEDIUM
Local
|
google
|
android
|
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB driver leaks address information via kernel logging. The Samsung IDs are SVE-2020-17602, SVE-2020-…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-25046
|
2024-11-21 14:16 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208240
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_adselfservice_plus manageengine_exchange_reporter_plus manageengine_ad360 manageengine_datasecurity_plus manageengine_recovermanager_plus manageengine_eventlog_analyzer
|
An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before bui…
|
CWE-287
Improper Authentication
|
CVE-2020-24786
|
2024-11-21 14:16 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|