|
208961
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A denial of service issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1. An attacker may be able to bypass Managed Frame Protection.
|
CWE-252
Unchecked Return Value
|
CVE-2020-27898
|
2024-11-21 14:22 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208962
|
3.3 |
LOW
Local
|
apple
|
itunes
|
An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling. This issue is fixed in iTunes 12.11 for Windows. A malicious applica…
|
NVD-CWE-noinfo
|
CVE-2020-27895
|
2024-11-21 14:22 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208963
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
The issue was addressed with additional user controls. This issue is fixed in macOS Big Sur 11.0.1. Users may be unable to remove metadata indicating where files were downloaded from.
|
NVD-CWE-noinfo
|
CVE-2020-27894
|
2024-11-21 14:22 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208964
|
7.8 |
HIGH
Local
|
almico
|
speedfan
|
There is a local privilege escalation vulnerability in Alfredo Milani Comparetti SpeedFan 4.52. Attackers can use constructed programs to increase user privileges
|
NVD-CWE-noinfo
|
CVE-2020-28175
|
2024-11-21 14:22 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208965
|
8.1 |
HIGH
Network
|
netscout
|
airmagnet_enterprise
|
NETSCOUT AirMagnet Enterprise 11.1.4 build 37257 and earlier has a sensor escalated privileges vulnerability that can be exploited to provide someone with administrative access to a sensor, with cred…
|
NVD-CWE-noinfo
|
CVE-2020-28251
|
2024-11-21 14:22 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208966
|
6.5 |
MEDIUM
Network
|
bitrix24
|
bitrix_framework
|
An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restriction of Excessive Authentication Attempts" vulnerability exists in the admin l…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-28206
|
2024-11-21 14:22 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208967
|
9.8 |
CRITICAL
Network
|
set-in_project
|
set-in
|
Prototype pollution vulnerability in 'set-in' versions 1.0.0 through 2.0.0 allows attacker to cause a denial of service and may lead to remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-28273
|
2024-11-21 14:22 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208968
|
9.8 |
CRITICAL
Network
|
keyget_project
|
keyget
|
Prototype pollution vulnerability in 'keyget' versions 1.0.0 through 2.2.0 allows attacker to cause a denial of service and may lead to remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-28272
|
2024-11-21 14:22 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208969
|
5.3 |
MEDIUM
Network
|
trendmicro
|
officescan apex_one
|
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version, …
|
NVD-CWE-noinfo
|
CVE-2020-28583
|
2024-11-21 14:22 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208970
|
5.3 |
MEDIUM
Network
|
trendmicro
|
officescan apex_one
|
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal number of…
|
NVD-CWE-noinfo
|
CVE-2020-28582
|
2024-11-21 14:22 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|