CVE Vulnerability Database

Search and browse 284 known security vulnerabilities. Filter by severity, vendor, product, and year.

284 vulnerabilities found
CVE-2020-28941
5.5 medium

An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack, aka CID-d41227544427. This occurs because of an invalid free when the line discipline is used more

Linux Linux Kernel Nov 19, 2020
CVE-2020-13799
6.8 medium

Western Digital has identified a security vulnerability in the Replay Protected Memory Block (RPMB) protocol as specified in multiple standards for storage device interfaces, including all versions of eMMC, UFS, and NVMe. The RPMB protocol is specified by industry standards bodies and is implemented

Westerndigital Inand Cl Em132 Firmware Nov 18, 2020
CVE-2020-7564
8.8 high

A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause write access and the execution

Schneider-Electric Modicon Tsxety4103 Firmware Nov 18, 2020
CVE-2020-7563
8.8 high

A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause corruption of data, a crash, or code execution when uploading a specially crafted

Schneider-Electric Modicon Tsxety4103 Firmware Nov 18, 2020
CVE-2020-7562
8.1 high

A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a segmentation fault or a buffer overflow when uploading a specially crafted file o

Schneider-Electric Modicon Tsxety4103 Firmware Nov 18, 2020
CVE-2020-15783
7.5 high

A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC TDC CPU555 (All versions), SINUMERIK 840D sl (All versions). Sending multiple specially crafted packets to the affected devices could cause a Denial-of-Service on p

Siemens Sinumerik 840D Sl Firmware Nov 12, 2020
CVE-2020-28271
9.8 critical

Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.

Sharpred Deephas Nov 12, 2020
CVE-2020-17091
7.8 high

Microsoft Teams Remote Code Execution Vulnerability

Microsoft Teams Nov 11, 2020
CVE-2020-17003
7.8 high

<p>A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.</p> <p>An attacker who successfully exploited the vulnerability would gain execution on a victim system.</p> <p>The security update addresses the vulnerability by correcting how the Base3D ren

Microsoft 3D Viewer Oct 16, 2020
CVE-2020-16918
7.8 high

<p>A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.</p> <p>An attacker who successfully exploited the vulnerability would gain execution on a victim system.</p> <p>The security update addresses the vulnerability by correcting how the Base3D ren

Microsoft 365 Apps Oct 16, 2020
CVE-2020-15791
6.5 medium

A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 CPU family (incl. SIPLUS variants) (All versions), SIMATIC WinAC RTX (F) 2010 (All versions), SINUMERIK 840D sl (All versions). The authentication protocol b

Siemens Simatic S7-300 Cpu 312 Firmware Sep 9, 2020
CVE-2020-15786
9.8 critical

A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), SIMATIC HMI Mobile Panels (All versions <= V16), SIMATIC HMI Unified Comfort Panels (All versions <=

Siemens Simatic Hmi Basic Panels 2Nd Generation Firmware Sep 9, 2020
CVE-2020-1574
5.5 medium

A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code. Exploitation of the vulnerability requires that a program process a specially crafted image

Microsoft Windows 10 Aug 17, 2020
CVE-2020-15368
5.5 medium

AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering a triple fault via a request to zero CR3.

Asrock Rgb Driver Firmware Jun 29, 2020
CVE-2020-9488
3.7 low

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

Apache Log4J Apr 27, 2020
CVE-2020-7489
9.8 critical

A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this vulnerability, DLL substitution, cou

Schneider-Electric Ecostruxure Machine Expert Apr 22, 2020
CVE-2020-7488
7.5 high

A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 controllers.

Schneider-Electric Ecostruxure Machine Expert Apr 22, 2020
CVE-2020-10932
4.7 medium

An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough side-channel measurements can recover the long-term ECDSA private key by (1) reconstructing the projective coordinate of the result of scalar multiplication by exploiting side chann

Arm Mbed Tls Apr 15, 2020
CVE-2020-11725
7.8 high

snd_ctl_elem_add in sound/core/control.c in the Linux kernel through 5.6.3 has a count=info->owner line, which later affects a private_size*count multiplication for unspecified "interesting side effects." NOTE: kernel engineers dispute this finding, because it could be relevant only if new callers w

Linux Linux Kernel Apr 12, 2020
CVE-2020-7477
7.5 high

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Quantum Ethernet Network module 140NOE771x1 (Versions 7.0 and prior), Quantum processors with integrated Ethernet – 140CPU65xxxxx (all Versions), and Premium processors with integrated Ethernet (all Versions), wh

Schneider-Electric 140Noe77101 Firmware Mar 23, 2020
CVE-2020-6990
9.8 critical

Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic key utilized to help protect the account password is hard coded into the RSLogix 500 binary file. An

Rockwellautomation Micrologix 1400 A Firmware Mar 16, 2020
CVE-2020-6988
7.5 high

Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, A remote, unauthenticated attacker can send a request from the RSLogix 500 software to the victim’s MicroLogix control

Rockwellautomation Micrologix 1400 A Firmware Mar 16, 2020
CVE-2020-6984
7.5 high

Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic function utilized to protect the password in MicroLogix is discoverable.

Rockwellautomation Micrologix 1400 A Firmware Mar 16, 2020
CVE-2019-18336
7.5 high

A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V3.X.17), SIMATIC TDC CP51M1 (All versions < V1.1.8), SIMATIC TDC CPU555 (All versions < V1.1.1), SINUMERIK 840D sl (All versions < V4.8.6), SINUMERIK 840D sl (All versions

Siemens Simatic S7-300 Cpu Firmware Mar 10, 2020