Export limit exceeded: 43141 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 43141 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (43141 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2020-13092 | 1 Scikit-learn | 1 Scikit-learn | 2024-11-21 | 9.8 Critical |
| scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the joblib.load() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the joblib.load() function is documented as unsafe and it is the user's responsibility to use the function in a secure manner | ||||
| CVE-2020-12927 | 1 Amd | 1 Vbios Flash Tool Software Development Kit | 2024-11-21 | 7.8 High |
| A potential vulnerability in a dynamically loaded AMD driver in AMD VBIOS Flash Tool SDK may allow any authenticated user to escalate privileges to NT authority system. | ||||
| CVE-2020-12926 | 1 Amd | 1 Trusted Platform Modules Reference | 2024-11-21 | 6.4 Medium |
| The Trusted Platform Modules (TPM) reference software may not properly track the number of times a failed shutdown happens. This can leave the TPM in a state where confidential key material in the TPM may be able to be compromised. AMD believes that the attack requires physical access of the device because the power must be repeatedly turned on and off. This potential attack may be used to change confidential information, alter executables signed by key material in the TPM, or create a denial of service of the device. | ||||
| CVE-2020-12912 | 1 Amd | 1 Energy Driver For Linux | 2024-11-21 | 5.5 Medium |
| A potential vulnerability in the AMD extension to Linux "hwmon" service may allow an attacker to use the Linux-based Running Average Power Limit (RAPL) interface to show various side channel attacks. In line with industry partners, AMD has updated the RAPL interface to require privileged access. | ||||
| CVE-2020-12835 | 1 Smartbear | 1 Readyapi | 2024-11-21 | 9.8 Critical |
| An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol component. | ||||
| CVE-2020-12829 | 3 Canonical, Debian, Qemu | 3 Ubuntu Linux, Debian Linux, Qemu | 2024-11-21 | 3.8 Low |
| In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback. A local attacker could abuse this flaw to crash the QEMU process in sm501_2d_operation() in hw/display/sm501.c on the host, resulting in a denial of service. | ||||
| CVE-2020-12680 | 1 Avira | 1 Free Antivirus | 2024-11-21 | 5.5 Medium |
| Avira Free Antivirus through 15.0.2005.1866 allows local users to discover user credentials. The functions of the executable file Avira.PWM.NativeMessaging.exe are aimed at collecting credentials stored in Chrome, Firefox, Opera, and Edge. The executable does not verify the calling program and thus a request such as fetchChromePasswords or fetchCredentials will succeed. NOTE: some third parties have stated that this is "not a vulnerability. | ||||
| CVE-2020-12485 | 1 Vivo | 1 Frame Touch Module | 2024-11-21 | 5.5 Medium |
| The frame touch module does not make validity judgments on parameter lengths when processing specific parameters,which caused out of the boundary when memory access.The vulnerability eventually leads to a local DOS on the device. | ||||
| CVE-2020-12463 | 1 Avira | 1 Software Updater | 2024-11-21 | 7.8 High |
| An elevation of privilege vulnerability exists in Avira Software Updater before 2.0.6.27476 due to improperly handling file hard links. This allows local users to obtain take control of arbitrary files. | ||||
| CVE-2020-12430 | 1 Redhat | 2 Enterprise Linux, Libvirt | 2024-11-21 | 6.5 Medium |
| An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving domain statistics when managing QEMU guests. This flaw allows unprivileged users with a read-only connection to cause a memory leak in the domstats command, resulting in a potential denial of service. | ||||
| CVE-2020-12356 | 2 Intel, Netapp | 2 Active Management Technology Firmware, Cloud Backup | 2024-11-21 | 4.4 Medium |
| Out-of-bounds read in subsystem in Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user to potentially enable information disclosure via local access. | ||||
| CVE-2020-12354 | 1 Intel | 1 Active Management Technology Software Development Kit | 2024-11-21 | 7.8 High |
| Incorrect default permissions in Windows(R) installer in Intel(R) AMT SDK versions before 14.0.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||||
| CVE-2020-12353 | 1 Intel | 1 Data Center Manager | 2024-11-21 | 6.5 Medium |
| Improper permissions in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable denial of service via network access. | ||||
| CVE-2020-12350 | 1 Intel | 1 Extreme Tuning Utility | 2024-11-21 | 7.8 High |
| Improper access control in the Intel(R) XTU before version 6.5.1.360 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||||
| CVE-2020-12349 | 1 Intel | 1 Data Center Manager | 2024-11-21 | 6.5 Medium |
| Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable information disclosure via network access. | ||||
| CVE-2020-12347 | 1 Intel | 1 Data Center Manager | 2024-11-21 | 8.8 High |
| Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable escalation of privilege via network access. | ||||
| CVE-2020-12346 | 1 Intel | 1 Battery Life Diagnostic Tool | 2024-11-21 | 7.8 High |
| Improper permissions in the installer for the Intel(R) Battery Life Diagnostic Tool before version 1.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||||
| CVE-2020-12345 | 1 Intel | 1 Data Center Manager | 2024-11-21 | 7.8 High |
| Improper permissions in the installer for the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||||
| CVE-2020-12338 | 1 Intel | 1 Open Webrtc Toolkit | 2024-11-21 | 9.8 Critical |
| Insufficient control flow management in the Open WebRTC Toolkit before version 4.3.1 may allow an unauthenticated user to potentially enable escalation of privilege via network access. | ||||
| CVE-2020-12337 | 1 Intel | 46 Nuc 8 Mainstream-g Kit Nuc8i5inh, Nuc 8 Mainstream-g Kit Nuc8i5inh Firmware, Nuc 8 Mainstream-g Kit Nuc8i7inh and 43 more | 2024-11-21 | 6.7 Medium |
| Improper buffer restrictions in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access. | ||||