Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2021-01-26 CVE-2020-29443 Out-of-bounds Read vulnerability in multiple products
ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.
local
high complexity
qemu debian CWE-125
3.9
2021-01-26 CVE-2020-4889 Unspecified vulnerability in IBM Spectrum Scale
IBM Spectrum Scale 5.0.0 through 5.0.5.4 and 5.1.0 could allow a local user to poison log files which could impact support and development efforts.
local
low complexity
ibm
3.3
2021-01-20 CVE-2020-25686 A flaw was found in dnsmasq before version 2.83.
network
high complexity
thekelleys fedoraproject debian arista
3.7
2021-01-20 CVE-2020-25685 Inadequate Encryption Strength vulnerability in multiple products
A flaw was found in dnsmasq before version 2.83.
network
high complexity
thekelleys fedoraproject debian arista CWE-326
3.7
2021-01-20 CVE-2020-25684 A flaw was found in dnsmasq before version 2.83.
network
high complexity
thekelleys fedoraproject debian arista
3.7
2021-01-13 CVE-2020-9203 Resource Exhaustion vulnerability in Huawei P30 Firmware
There is a resource management errors vulnerability in Huawei P30.
local
low complexity
huawei CWE-400
3.3
2021-01-12 CVE-2020-14341 Unspecified vulnerability in Redhat Single Sign-On
The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing, and originating from the RHSSO installation.
network
low complexity
redhat
2.7
2021-01-12 CVE-2021-23239 Link Following vulnerability in multiple products
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.
2.5
2021-01-11 CVE-2020-24003 Unspecified vulnerability in Microsoft Skype 8.59.0.77
Microsoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Skype Client's microphone and camera access.
local
low complexity
microsoft
3.3
2021-01-05 CVE-2020-23250 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Gigamon Gigavue-Os
GigaVUE-OS (GVOS) 5.4 - 5.9 uses a weak algorithm for a hash stored in internal database.
local
low complexity
gigamon CWE-327
2.3