cve.mitre.org
Kanalga Telegram’da o‘tish
Common Vulnerabilities and Exposures
Ko'proq ko'rsatishMamlakat belgilanmaganToif belgilanmagan
130
Obunachilar
Ma'lumot yo'q24 soatlar
Ma'lumot yo'q7 kun
+1630 kun
Postlar arxiv
CVE-2020-2049 A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the... https://t.co/7xMw2Nablm— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 08:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-2020 An improper handling of exceptional conditions vulnerability in Cortex XDR Agent allows a local authenticated Windows user to create files in the software's internal program directory that prevents the Cortex XDR Agent from starting. The e... https://t.co/acl73CzNzK— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 08:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-29661 A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b. https://t.co/rv9iyF6S1W— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 07:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-29660 A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24. https://t.co/d9GH8bx1zJ— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 07:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-29659 A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execute code as SYSTEM by overflowing the sid parameter via a GET /settings&sid= attack. https://t.co/GqQ4pk8O8X— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 07:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-26838 SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacker authenticated with (high) developer privileges to submit a crafted request to generate ... https://t.co/WuTj5ItSOC— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 07:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-26837 SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious script that can exploit an existing path traversal vulnerability to compromise confidentiality exposing elements of t... https://t.co/Hb6Pe8btcM— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 07:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-26836 SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability, an attacker can enter a link to malicious site which could trick the user to enter crede... https://t.co/kjfelkdkHb— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 07:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-26835 SAP NetWeaver AS ABAP, versions - 740, 750, 751, 752, 753, 754 , does not sufficiently encode URL which allows an attacker to input malicious java script in the URL which could be executed in the browser resulting in Reflected Cross-Site ... https://t.co/Gm5KQZJfyK— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 07:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-26834 SAP HANA Database, version - 2.0, does not correctly validate the username when performing SAML bearer token-based user authentication. It is possible to manipulate a valid existing SAML bearer token to authenticate as a user whose name i... https://t.co/fvKMBRwMkX— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 07:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-26832 SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), versions - 101, 102, 103, 104, 105, allows a h... https://t.co/wudAGIbZl2— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 07:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-26831 SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML entities during crystal report generation due to missing XML validation, An attacker with basic privileges can inject ... https://t.co/9ID32QQlVQ— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 07:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-26830 SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks for an authenticated user. Due to inadequate access control, a network attacker authenticated as a regular user can use ... https://t.co/y4ximExM1I— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 07:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-26829 SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication check, that are outside the cluster and even outside the netwo... https://t.co/wkiCxEvjOc— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 07:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-26828 SAP Disclosure Management, version - 10.1, provides capabilities for authorized users to upload and download content of specific file type. In some file types it is possible to enter formulas which can call external applications or execut... https://t.co/fwXfd1iBGo— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 07:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-26826 Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) without proper file format validation, leading to Unrestricted File Upload. https://t.co/wbhVX46elc— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 07:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-26816 SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in the SAP NetWeaver AS Java Key Storage service stored in the database in the DER encoded format and is not encr... https://t.co/tSkGfKDPNm— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 07:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-26261 jupyterhub-systemdspawner enables JupyterHub to spawn single-user notebook servers using systemd. In jupyterhub-systemdspawner before version 0.15 user API tokens issued to single-user servers are specified in the environment of systemd u... https://t.co/qD55VzjFe6— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 07:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-26260 BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a user with permissions to edit a page could set certain image URL's to manipulate functionality in the exporting system... https://t.co/8k2V0xjVAs— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 07:45PM
via Twitter https://twitter.com/CVEnew
CVE-2020-25199 A heap-based buffer overflow vulnerability exists within the WECON LeviStudioU Release Build 2019-09-21 and prior when processing project files. Opening a specially crafted project file could allow an attacker to exploit and execute code ... https://t.co/abb5pO6YGJ— CVE (@CVEnew) December 9, 2020
December 09, 2020 at 07:45PM
via Twitter https://twitter.com/CVEnew
