CVE, Title, Vendor |
Description |
CVSS v2 Base Score |
Date Created |
Date Updated |
CVE-2020-0096
Google Android Elevation of Privilege Vulnerability
Google
|
Android is a mobile operating system based on a modified version of the Linux kernel and other open source software, designed primarily for touchscreen mobile devices such as smartphones and tablets. In startActivities of ActivityStartController.java, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. |
CVSSv3BaseScore:7.8(AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) |
05/14/2020 |
05/18/2020 |
CVE-2020-9484
Apache Tomcat Remote Code Execution Vulnerability
Apache
|
When using Apache Tomcat versions if a) an attacker is able to control the contents and name of a file on the server and b) the server is configured to use the Persistence Manager with a FileStore |
CVSSv3BaseScore:9.8(AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
05/20/2020 |
05/28/2020 |
CVE-2020-1048
Microsoft Windows Print Spooler Elevation of Privilege Vulnerability
Microsoft
|
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. |
CVSSv3BaseScore:7.8(AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) |
05/21/2020 |
05/26/2020 |
CVE-2020-3153
Cisco AnyConnect Secure Mobility Client Vulnerability
Cisco
|
A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. |
CVSSv3BaseScore:6.5(AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N) |
02/19/2020 |
04/21/2020 |
CVE-2020-8617
ISC BIND Denial of Service Vulnerability
Multi-Vendor
|
Using a specially crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make use of it, almost all current BIND servers are vulnerable. A remote attacker could use this issue to cause Bind to crash, resulting in a denial of service, or possibly perform other attacks. |
CVSSv3BaseScore:7.5(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) |
05/19/2020 |
06/01/2020 |
CVE-2019-7192
QNAP Pre-Auth Root Remote Code Execution Vulnerability
Qnap
|
QTS (QNAP Turbo NAS System) is a Turbo NAS Operating System, providing file storage, backup, disaster recovery, security management and virtualization applications for businesses multimedia applications. This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. |
CVSSv3BaseScore:9.8(AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) |
12/05/2019 |
05/28/2020 |
CVE-2020-12720
vBulletin Remote SQL Injection Vulnerability
vBulletin
|
A remote SQL injection vulnerability exists in vBulletin. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system. |
CVSSv3BaseScore:9.8(AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) |
05/07/2020 |
06/02/2020 |
CVE-2020-1048
Microsoft Windows Print Spooler Elevation of Privilege Vulnerability
Microsoft
|
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. |
CVSSv3BaseScore:7.8(AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) |
05/21/2020 |
05/26/2020 |