CVE-2020-16000 to CVE-2020-16999
90 CVEs with public proof-of-concept exploits.
- CVE-2020-160091 PoCKEVInappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap…
- CVE-2020-160123 PoCsSide-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data…
- CVE-2020-160409 PoCsInsufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption…
- CVE-2020-160941 PoCIn imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited…
- CVE-2020-161252 PoCsgdm3 would start gnome-initial-setup if it cannot contact accountservice
- CVE-2020-161262 PoCsaccountsservice drops ruid, allows unprivileged users to send it signals
- CVE-2020-161272 PoCsaccountsservice .pam_environment infinite loop
- CVE-2020-161351 PoClibssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.
- CVE-2020-161373 PoCsA privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to reset the…
- CVE-2020-161383 PoCsA denial-of-service issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to remotely disable the…
- CVE-2020-161394 PoCsA denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely…
- CVE-2020-161431 PoCThe seafile-client client 7.0.8 for Seafile is vulnerable to DLL hijacking because it loads exchndl.dll from the current working directory.
- CVE-2020-161472 PoCsThe login page in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via Unauthenticated code injection…
- CVE-2020-161482 PoCsThe ping page of the administration panel in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via…
- CVE-2020-161523 PoCsThe NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows…
- CVE-2020-161541 PoCThe App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.
- CVE-2020-161551 PoCThe CPAN::Checksums package 2.12 for Perl does not uniquely define signed data.
- CVE-2020-161561 PoCCPAN 2.28 allows Signature Verification Bypass.
- CVE-2020-161571 PoCA Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu.
- CVE-2020-161581 PoCGoPro gpmf-parser through 1.5 has a stack out-of-bounds write vulnerability in GPMF_ExpandComplexTYPE(). Parsing malicious input can…
- CVE-2020-161591 PoCGoPro gpmf-parser 1.5 has a heap out-of-bounds read and segfault in GPMF_ScaledData(). Parsing malicious input can result in a crash or…
- CVE-2020-161601 PoCGoPro gpmf-parser 1.5 has a division-by-zero vulnerability in GPMF_Decompress(). Parsing malicious input can result in a crash.
- CVE-2020-161611 PoCGoPro gpmf-parser 1.5 has a division-by-zero vulnerability in GPMF_ScaledData(). Parsing malicious input can result in a crash.
- CVE-2020-161671 PoCMissing Authentication for Critical Function in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to…
- CVE-2020-161681 PoCOrigin Validation Error in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to access the REST API and…
- CVE-2020-161691 PoCAuthentication Bypass Using an Alternate Path or Channel in temi Robox OS prior to120, temi Android app up to 1.3.7931 allows remote…
- CVE-2020-161701 PoCUse of Hard-coded Credentials in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to listen in on any…
- CVE-2020-161712 PoCsAn issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/ accept an…
- CVE-2020-161941 PoCAn Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have…
- CVE-2020-162041 PoCThe affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to execute commands…
- CVE-2020-162052 PoCsUsing a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code (Firmware Versions…
- CVE-2020-162062 PoCsThe affected product is vulnerable to stored cross-site scripting, which may allow an attacker to remotely execute arbitrary code to gain…
- CVE-2020-162101 PoCThe affected product is vulnerable to reflected cross-site scripting, which may allow an attacker to remotely execute arbitrary code and…
- CVE-2020-162481 PoCPrometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be…
- CVE-2020-162561 PoCThe API on Winston 1.5.4 devices is vulnerable to CSRF.
- CVE-2020-162571 PoCWinston 1.5.4 devices are vulnerable to command injection via the API.
- CVE-2020-162581 PoCWinston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials.
- CVE-2020-162591 PoCWinston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents and is not…
- CVE-2020-162601 PoCWinston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities…
- CVE-2020-162611 PoCWinston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access.
- CVE-2020-162621 PoCWinston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation.
- CVE-2020-162631 PoCWinston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewed by arbitrary…
- CVE-2020-162661 PoCAn XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attacker to inject…
- CVE-2020-162691 PoCradare2 4.5.0 misparses DWARF information in executable files, causing a segmentation fault in parse_typedef in type_dwarf.c via a…
- CVE-2020-162702 PoCsOLIMPOKS under 3.3.39 allows Auth/Admin ErrorMessage XSS. Remote Attacker can use discovered vulnerability to inject malicious JavaScript…
- CVE-2020-162871 PoCA buffer overflow vulnerability in lprn_is_black() in contrib/lips4/gdevlprn.c of Artifex Software GhostScript v9.50 allows a remote…
- CVE-2020-162881 PoCA buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c of Artifex Software GhostScript v9.50 allows a remote…
- CVE-2020-162891 PoCA buffer overflow vulnerability in cif_print_page() in devices/gdevcif.c of Artifex Software GhostScript v9.50 allows a remote attacker to…
- CVE-2020-162901 PoCA buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote…
- CVE-2020-162911 PoCA buffer overflow vulnerability in contrib/gdevdj9.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a…
- CVE-2020-162921 PoCA buffer overflow vulnerability in mj_raster_cmd() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote…
- CVE-2020-162931 PoCA null pointer dereference vulnerability in compose_group_nonknockout_nonblend_isolated_allmask_common() in base/gxblend.c of Artifex…
- CVE-2020-162941 PoCA buffer overflow vulnerability in epsc_print_page() in devices/gdevepsc.c of Artifex Software GhostScript v9.50 allows a remote attacker…
- CVE-2020-162951 PoCA null pointer dereference vulnerability in clj_media_size() in devices/gdevclj.c of Artifex Software GhostScript v9.50 allows a remote…
- CVE-2020-162961 PoCA buffer overflow vulnerability in GetNumWrongData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript from v9.18 to v9.50…
- CVE-2020-162971 PoCA buffer overflow vulnerability in FloydSteinbergDitheringC() in contrib/gdevbjca.c of Artifex Software GhostScript v9.18 to v9.50 allows…
- CVE-2020-162981 PoCA buffer overflow vulnerability in mj_color_correct() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote…
- CVE-2020-162991 PoCA Division by Zero vulnerability in bj10v_print_page() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote…
- CVE-2020-163001 PoCA buffer overflow vulnerability in tiff12_print_page() in devices/gdevtfnx.c of Artifex Software GhostScript v9.50 allows a remote…
- CVE-2020-163011 PoCA buffer overflow vulnerability in okiibm_print_page1() in devices/gdevokii.c of Artifex Software GhostScript v9.50 allows a remote…
- CVE-2020-163021 PoCA buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote…
- CVE-2020-163031 PoCA use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a…
- CVE-2020-163041 PoCA buffer overflow vulnerability in image_render_color_thresh() in base/gxicolor.c of Artifex Software GhostScript v9.18 to v9.50 allows a…
- CVE-2020-163051 PoCA buffer overflow vulnerability in pcx_write_rle() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote…
- CVE-2020-163061 PoCA null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a…
- CVE-2020-163071 PoCA null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex Software GhostScript v9.50 allows a…
- CVE-2020-163081 PoCA buffer overflow vulnerability in p_print_image() in devices/gdevcdj.c of Artifex Software GhostScript v9.50 allows a remote attacker to…
- CVE-2020-163091 PoCA buffer overflow vulnerability in lxm5700m_print_page() in devices/gdevlxm.c of Artifex Software GhostScript v9.50 allows a remote…
- CVE-2020-163101 PoCA division by zero vulnerability in dot24_print_page() in devices/gdevdm24.c of Artifex Software GhostScript v9.50 allows a remote…
- CVE-2020-165871 PoCA heap-based buffer overflow vulnerability exists in Academy Software Foundation OpenEXR 2.3.0 in chunkOffsetReconstruction in…
- CVE-2020-165881 PoCA Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3.0 in generatePreview in makePreview.cpp that can cause a…
- CVE-2020-165901 PoCA double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils 2.35 in the process_symbol_table, as…
- CVE-2020-165911 PoCA Denial of Service vulnerability exists in the Binary File Descriptor (BFD) in GNU Binutils 2.35 due to an invalid read in…
- CVE-2020-165921 PoCA use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as…
- CVE-2020-165931 PoCA Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils…
- CVE-2020-165991 PoCA Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils…
- CVE-2020-166022 PoCsRazer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in…
- CVE-2020-166081 PoCNotable 1.8.4 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in webPreferences is…
- CVE-2020-166301 PoCTI’s BLE stack caches and reuses the LTK’s property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key…
- CVE-2020-168468 PoCsKEVAn issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can…
- CVE-2020-168753 PoCsMicrosoft Exchange Server Remote Code Execution Vulnerability
- CVE-2020-1689814 PoCsWindows TCP/IP Remote Code Execution Vulnerability
- CVE-2020-168991 PoCWindows TCP/IP Denial of Service Vulnerability
- CVE-2020-169201 PoCWindows Application Compatibility Client Library Elevation of Privilege Vulnerability
- CVE-2020-169382 PoCsWindows Kernel Information Disclosure Vulnerability
- CVE-2020-169391 PoCGroup Policy Elevation of Privilege Vulnerability
- CVE-2020-169473 PoCsMicrosoft Outlook Remote Code Execution Vulnerability
- CVE-2020-169523 PoCsMicrosoft SharePoint Remote Code Execution Vulnerability
- CVE-2020-169851 PoCAzure Sphere Information Disclosure Vulnerability
- CVE-2020-169911 PoCAzure Sphere Unsigned Code Execution Vulnerability