Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2021-02-16 CVE-2020-29023 Improper Encoding or Escaping of Output vulnerability in Secomea products
Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's computer when opened in a spreadsheet program (like Excel).
network
low complexity
secomea CWE-116
3.5
2021-02-11 CVE-2019-19004 Integer Overflow or Wraparound vulnerability in multiple products
A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap image.
local
low complexity
autotrace-project fedoraproject CWE-190
3.3
2021-02-11 CVE-2020-1717 Information Exposure Through an Error Message vulnerability in Redhat products
A flaw was found in Keycloak 7.0.1.
network
low complexity
redhat CWE-209
2.7
2021-02-11 CVE-2020-10734 Unspecified vulnerability in Redhat products
A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection.
local
low complexity
redhat
3.3
2021-02-11 CVE-2021-20402 Information Exposure Through an Error Message vulnerability in IBM Security Verify Information Queue 1.0.6/1.0.7
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
ibm CWE-209
2.7
2021-02-10 CVE-2021-21296 Unspecified vulnerability in Fleetdm Fleet
Fleet is an open source osquery manager.
network
low complexity
fleetdm
2.7
2021-02-10 CVE-2021-22133 Information Exposure Through Log Files vulnerability in Elastic APM Agent
The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an application panic.
low complexity
elastic CWE-532
2.4
2021-02-09 CVE-2020-17428 Out-of-bounds Read vulnerability in Foxitsoftware Foxit Studio Photo 3.6.6.922
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922.
local
low complexity
foxitsoftware CWE-125
3.3
2021-02-09 CVE-2020-17422 Out-of-bounds Read vulnerability in Foxitsoftware Foxit Studio Photo 3.6.6.922
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922.
local
low complexity
foxitsoftware CWE-125
3.3
2021-02-09 CVE-2020-17420 Out-of-bounds Read vulnerability in Foxitsoftware Foxit Studio Photo 3.6.6.922
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922.
local
low complexity
foxitsoftware CWE-125
3.3