Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2020-10-22 CVE-2020-27560 Divide By Zero vulnerability in multiple products
ImageMagick 7.0.10-34 allows Division by Zero in OptimizeLayerFrames in MagickCore/layer.c, which may cause a denial of service.
local
low complexity
imagemagick debian opensuse CWE-369
3.3
2020-10-21 CVE-2020-3585 Information Exposure Through Discrepancy vulnerability in Cisco products
A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain access to sensitive information.
network
high complexity
cisco CWE-203
3.7
2020-10-19 CVE-2020-15262 Insufficient Verification of Data Authenticity vulnerability in Webpack-Subresource-Integrity Project Webpack-Subresource-Integrity
In webpack-subresource-integrity before version 1.5.1, all dynamically loaded chunks receive an invalid integrity hash that is ignored by the browser, and therefore the browser cannot validate their integrity.
3.7
2020-10-16 CVE-2020-9959 Improper Locking vulnerability in Apple Iphone OS
A lock screen issue allowed access to messages on a locked device.
low complexity
apple CWE-667
2.4
2020-10-16 CVE-2020-9933 Unspecified vulnerability in Apple products
An authorization issue was addressed with improved state management.
local
low complexity
apple
3.3
2020-10-16 CVE-2020-9912 Unspecified vulnerability in Apple Safari
A logic issue was addressed with improved restrictions.
local
low complexity
apple
3.3
2020-10-14 CVE-2020-25824 Missing Authentication for Critical Function vulnerability in Telegram Desktop
Telegram Desktop through 2.4.3 does not require passcode entry upon pushing the Export key within the Export Telegram Data wizard.
low complexity
telegram CWE-306
2.4
2020-10-14 CVE-2020-0422 Unspecified vulnerability in Google Android
In constructImportFailureNotification of NotificationImportExportListener.java, there is a possible permissions bypass due to an unsafe PendingIntent.
local
low complexity
google
3.3
2020-10-14 CVE-2020-0412 Missing Authorization vulnerability in Google Android
In setProcessMemoryTrimLevel of ActivityManagerService.java, there is a missing permission check.
local
low complexity
google CWE-862
3.3
2020-10-13 CVE-2020-17411 Unspecified vulnerability in Foxitsoftware 3D
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 10.0.0.35798.
local
low complexity
foxitsoftware
3.3