Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2020-10-12 CVE-2020-15250 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability.
local
low complexity
junit debian apache oracle CWE-732
5.5
2020-10-12 CVE-2020-25825 Unspecified vulnerability in Octopus Deploy
In Octopus Deploy 3.1.0 to 2020.4.0, certain scripts can reveal sensitive information to the user in the task logs.
network
low complexity
octopus
5.0
2020-10-12 CVE-2020-8821 Injection vulnerability in Webmin
An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint.
network
webmin CWE-74
3.5
2020-10-12 CVE-2020-8820 Cross-site Scripting vulnerability in Webmin
An XSS Vulnerability exists in Webmin 1.941 and earlier affecting the Cluster Shell Commands Endpoint.
network
webmin CWE-79
3.5
2020-10-12 CVE-2020-12670 Cross-site Scripting vulnerability in Webmin
XSS exists in Webmin 1.941 and earlier affecting the Save function of the Read User Email Module / mailboxes Endpoint when attempting to save HTML emails.
network
webmin CWE-79
4.3
2020-10-12 CVE-2020-9240 Classic Buffer Overflow vulnerability in Huawei Taurus-An00B Firmware
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a buffer overflow vulnerability.
local
low complexity
huawei CWE-120
2.1
2020-10-12 CVE-2020-9110 Information Exposure vulnerability in Huawei Taurus-An00B Firmware
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an information disclosure vulnerability.
local
low complexity
huawei CWE-200
2.1
2020-10-12 CVE-2020-4741 Cross-site Scripting vulnerability in IBM Infosphere Information Server 11.5/11.7
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to stored cross-site scripting.
network
ibm CWE-79
3.5
2020-10-12 CVE-2020-4740 Injection vulnerability in IBM Infosphere Information Server 11.5/11.7
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to HTML injection.
4.3
2020-10-12 CVE-2020-4689 Injection vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 is vulnerable to CVS Injection.
network
ibm CWE-74
8.5