|
208841
|
5.5 |
MEDIUM
Local
|
avast
|
secureline_vpn
|
The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Manager symbolic link from the log directory (which has weak permissions).
|
CWE-59
Link Following
|
CVE-2020-25289
|
2024-11-21 14:17 |
2020-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208842
|
7.2 |
HIGH
Network
|
pligg_project
|
pligg
|
Pligg 2.0.3 allows remote authenticated users to execute arbitrary commands because the template editor can edit any file, as demonstrated by an admin/admin_editor.php the_file=..%2Findex.php&open=Op…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-25287
|
2024-11-21 14:17 |
2020-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208843
|
5.3 |
MEDIUM
Network
|
wordpress
|
wordpress
|
In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.
|
NVD-CWE-noinfo
|
CVE-2020-25286
|
2024-11-21 14:17 |
2020-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208844
|
6.4 |
MEDIUM
Local
|
linux debian canonical
|
linux_kernel debian_linux ubuntu_linux
|
A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local attackers to corrupt memory, cause a NULL pointer dereference, or possibly hav…
|
CWE-362 CWE-787 CWE-476
Race Condition Out-of-bounds Write NULL Pointer Dereference
|
CVE-2020-25285
|
2024-11-21 14:17 |
2020-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208845
|
4.1 |
MEDIUM
Local
|
linux debian opensuse
|
linux_kernel debian_linux leap
|
The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map …
|
CWE-863
Incorrect Authorization
|
CVE-2020-25284
|
2024-11-21 14:17 |
2020-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208846
|
9.8 |
CRITICAL
Network
|
google
|
android
|
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. BT manager allows attackers to bypass intended access restrictions on a certain mode. The LG ID is LVE-SMP…
|
CWE-862
Missing Authorization
|
CVE-2020-25283
|
2024-11-21 14:17 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208847
|
9.8 |
CRITICAL
Network
|
google
|
android
|
An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Integrated Circuit Card) allows attackers to bypass intended access restrictions on…
|
CWE-862
Missing Authorization
|
CVE-2020-25282
|
2024-11-21 14:17 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208848
|
7.5 |
HIGH
Network
|
google
|
android
|
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Applications with sensitive security settings (such as the package verifier application) mishandle u…
|
NVD-CWE-noinfo
|
CVE-2020-25281
|
2024-11-21 14:17 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208849
|
6.8 |
MEDIUM
Physics
|
google
|
android
|
An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos and MediaTek chipsets) software. Unauthenticated attackers can execute LTE/5G commands by sending a debugging command over USB. …
|
NVD-CWE-noinfo
|
CVE-2020-25280
|
2024-11-21 14:17 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208850
|
9.8 |
CRITICAL
Network
|
google
|
android
|
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The baseband component has a buffer overflow via an abnormal SETUP message, leading to e…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-25279
|
2024-11-21 14:17 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|