Search Results (355348 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-27644 1 1e 1 Client 2024-11-21 8.8 High
The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.exe. This may allow remote authenticated users and local users to gain elevated privileges by placing a malicious cryptbase.dll file in %WINDIR%\Temp\.
CVE-2020-27643 1 1e 1 Client 2024-11-21 6.5 Medium
The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and modify files in protected directories (where they would not normally have access to create or modify files) via the creation of a junction point to a system directory. This leads to partial privilege escalation.
CVE-2020-27642 1 Bigbluebutton 1 Greenlight 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
CVE-2020-27640 1 Mitel 4 Mivoice 6930, Mivoice 6930 Firmware, Mivoice 6940 and 1 more 2024-11-21 8.1 High
The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet phones with firmware before 1.5.3 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.
CVE-2020-27639 1 Mitel 6 6873i Sip, 6873i Sip Firmware, 6930 Sip and 3 more 2024-11-21 8.1 High
The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.
CVE-2020-27638 3 Debian, Fastd Project, Fedoraproject 3 Debian Linux, Fastd, Fedora 2024-11-21 7.5 High
receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.
CVE-2020-27637 1 R-project 1 Cran 2024-11-21 9.8 Critical
The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages installed via the R CMD install cli command or the install.packages() function from the interpreter. Update to version 4.0.3
CVE-2020-27636 1 Microchip 1 Mplab Network Creator 2024-11-21 9.1 Critical
In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.
CVE-2020-27635 1 Capgemini 1 Picotcp 2024-11-21 9.1 Critical
In PicoTCP 1.7.0, TCP ISNs are improperly random.
CVE-2020-27634 1 Contiki-ng 1 Contiki-ng 2024-11-21 9.1 Critical
In Contiki 4.5, TCP ISNs are improperly random.
CVE-2020-27633 1 Butok 1 Fnet 2024-11-21 9.1 Critical
In FNET 4.6.3, TCP ISNs are improperly random.
CVE-2020-27632 1 Siemens 4 Simatic Mv420, Simatic Mv420 Firmware, Simatic Mv440 and 1 more 2024-11-21 7.5 High
In SIMATIC MV400 family versions prior to v7.0.6, the ISN generator is initialized with a constant value and has constant increments. An attacker could predict and hijack TCP sessions.
CVE-2020-27631 1 Oryx-embedded 1 Cyclonetcp 2024-11-21 9.8 Critical
In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random.
CVE-2020-27630 1 Silabs 1 Uc\/tcp-ip 2024-11-21 9.8 Critical
In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random.
CVE-2020-27629 1 Jetbrains 1 Teamcity 2024-11-21 5.3 Medium
In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there are no internal artifacts.
CVE-2020-27628 1 Jetbrains 1 Teamcity 2024-11-21 4.3 Medium
In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records.
CVE-2020-27627 1 Jetbrains 1 Teamcity 2024-11-21 6.1 Medium
JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
CVE-2020-27626 1 Jetbrains 1 Youtrack 2024-11-21 5.3 Medium
JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.
CVE-2020-27625 1 Jetbrains 1 Youtrack 2024-11-21 5.3 Medium
In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues.
CVE-2020-27624 1 Jetbrains 1 Youtrack 2024-11-21 5.3 Medium
JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.