Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2020-10-02 CVE-2020-25741 NULL Pointer Dereference vulnerability in Qemu 5.0.0
fdctrl_write_data in hw/block/fdc.c in QEMU 5.0.0 has a NULL pointer dereference via a NULL block pointer for the current drive.
local
low complexity
qemu CWE-476
3.2
2020-10-01 CVE-2020-15671 Race Condition vulnerability in Mozilla Firefox
When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary.
network
high complexity
mozilla CWE-362
3.1
2020-09-30 CVE-2020-14378 Integer Underflow (Wrap or Wraparound) vulnerability in multiple products
An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop.
local
low complexity
dpdk opensuse canonical CWE-191
3.3
2020-09-30 CVE-2020-4629 Information Exposure Through an Error Message vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message.
local
low complexity
ibm CWE-209
3.3
2020-09-30 CVE-2020-15731 Improper Input Validation vulnerability in Bitdefender Engines 7.84063/7.84892/7.84897
An improper Input Validation vulnerability in the code handling file renaming and recovery in Bitdefender Engines allows an attacker to write an arbitrary file in a location hardcoded in a specially-crafted malicious file name.
local
low complexity
bitdefender CWE-20
3.6
2020-09-25 CVE-2020-25084 Use After Free vulnerability in multiple products
QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked.
local
low complexity
qemu debian CWE-416
3.2
2020-09-18 CVE-2020-16230 Unspecified vulnerability in Hms-Networks Ewon Cosy Firmware and Ewon Flexy Firmware
All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources.
local
low complexity
hms-networks
2.3
2020-09-18 CVE-2020-14525 Unspecified vulnerability in Philips Clinical Collaboration Platform 12.2.1
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior.
low complexity
philips
3.5
2020-09-17 CVE-2020-15186 Injection vulnerability in Helm
In Helm before versions 2.16.11 and 3.3.2 plugin names are not sanitized properly.
network
low complexity
helm CWE-74
2.7
2020-09-17 CVE-2020-15185 Unspecified vulnerability in Helm
In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one always used.
network
low complexity
helm
2.7