Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2020-11-05 CVE-2020-24426 Unspecified vulnerability in Adobe products
Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory.
local
low complexity
adobe
3.3
2020-11-05 CVE-2018-1725 Unspecified vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.3 and 7.4 n a multi tenant configuration could be vulnerable to information disclosure.
local
low complexity
ibm
2.3
2020-11-03 CVE-2019-4349 Information Exposure vulnerability in IBM Maximo Anywhere
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 applications can be installed on a deprecated operating system version that could compromised the confidentiality and integrity of the service.
low complexity
ibm CWE-200
3.5
2020-11-02 CVE-2020-8173 Missing Encryption of Sensitive Data vulnerability in Nextcloud Server
A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.
network
high complexity
nextcloud CWE-311
2.2
2020-10-31 CVE-2020-15703 Path Traversal vulnerability in Aptdaemon Project Aptdaemon 1.1.1
There is no input validation on the Locale property in an apt transaction.
local
low complexity
aptdaemon-project CWE-22
3.3
2020-10-29 CVE-2020-27656 Cleartext Transmission of Sensitive Information vulnerability in Synology Diskstation Manager
Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors.
network
high complexity
synology CWE-319
3.7
2020-10-29 CVE-2020-27650 Missing Encryption of Sensitive Data vulnerability in Synology Diskstation Manager and Skynas Firmware
Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
network
high complexity
synology CWE-311
3.7
2020-10-28 CVE-2020-25374 Insufficient Session Expiration vulnerability in Cyberark Privileged Session Manager 10.9.0.15
CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error popup message after two hours of idle time.
network
high complexity
cyberark CWE-613
2.6
2020-10-27 CVE-2020-9786 Unspecified vulnerability in Apple mac OS X
This issue was addressed with improved checks This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra.
local
low complexity
apple
3.3
2020-10-27 CVE-2019-8857 Improper Input Validation vulnerability in Apple Iphone OS
The issue was addressed with improved validation when an iCloud Link is created.
local
low complexity
apple CWE-20
3.3