Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2021-01-13 CVE-2020-9203 Resource Exhaustion vulnerability in Huawei P30 Firmware
There is a resource management errors vulnerability in Huawei P30.
local
low complexity
huawei CWE-400
3.3
2021-01-12 CVE-2020-14341 Unspecified vulnerability in Redhat Single Sign-On
The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing, and originating from the RHSSO installation.
network
low complexity
redhat
2.7
2021-01-12 CVE-2021-23239 Link Following vulnerability in multiple products
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.
2.5
2021-01-11 CVE-2020-24003 Unspecified vulnerability in Microsoft Skype 8.59.0.77
Microsoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Skype Client's microphone and camera access.
local
low complexity
microsoft
3.3
2021-01-05 CVE-2020-23250 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Gigamon Gigavue-Os
GigaVUE-OS (GVOS) 5.4 - 5.9 uses a weak algorithm for a hash stored in internal database.
local
low complexity
gigamon CWE-327
2.3
2021-01-04 CVE-2020-4919 Unspecified vulnerability in IBM Cloud PAK System
IBM Cloud Pak System 2.3 has insufficient logout controls which could allow an authenticated privileged user to impersonate another user on the system.
network
low complexity
ibm
3.8
2020-12-31 CVE-2020-11947 Out-of-bounds Read vulnerability in Qemu 4.1.0
iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated information from process memory to an attacker.
local
low complexity
qemu CWE-125
3.8
2020-12-27 CVE-2020-35448 Out-of-bounds Read vulnerability in multiple products
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1.
local
low complexity
gnu netapp CWE-125
3.3
2020-12-24 CVE-2020-2505 Information Exposure Through an Error Message vulnerability in Qnap QES
If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages.
local
low complexity
qnap CWE-209
2.3
2020-12-18 CVE-2020-24693 Unspecified vulnerability in Mitel Micontact Center Business
The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow a local attacker to view system information due to insufficient output sanitization.
local
low complexity
mitel
3.3