Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2020-07-14 CVE-2020-12025 XXE vulnerability in Rockwellautomation Studio 5000 Logix Designer 32.00/32.01/32.02
Rockwell Automation Logix Designer Studio 5000 Versions 32.00, 32.01, and 32.02 vulnerable to an xml external entity (XXE) vulnerability, which may allow an attacker to view hostnames or other resources from the program.
local
low complexity
rockwellautomation CWE-611
3.3
2020-07-02 CVE-2020-15469 NULL Pointer Dereference vulnerability in multiple products
In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.
local
low complexity
qemu debian CWE-476
2.3
2020-07-02 CVE-2020-2218 Insufficiently Protected Credentials vulnerability in HP Application Lifecycle Management Quality Center Project HP Application Lifecycle Management Quality Center
Jenkins HP ALM Quality Center Plugin 1.6 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
3.3
2020-07-01 CVE-2019-4706 Information Exposure Through Log Files vulnerability in IBM Security Identity Manager Virtual Appliance 7.0.2
IBM Security Identity Manager Virtual Appliance 7.0.2 writes information to log files which can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
network
low complexity
ibm CWE-532
2.7
2020-07-01 CVE-2019-4705 Unspecified vulnerability in IBM Security Identity Manager Virtual Appliance 7.0.2
IBM Security Identity Manager Virtual Appliance 7.0.2 discloses sensitive information to unauthorized users.
network
low complexity
ibm
2.7
2020-06-29 CVE-2020-12039 Use of Hard-coded Credentials vulnerability in Baxter Sigma Spectrum Infusion System Firmware 6.0/6.05/8.0
Baxter Sigma Spectrum Infusion Pumps Sigma Spectrum Infusion System v's6.x model 35700BAX & Baxter Spectrum Infusion System v's8.x model 35700BAX2 contain hardcoded passwords when physically entered on the keypad provide access to biomedical menus including device settings, view calibration values, network configuration of Sigma Spectrum WBM if installed.
low complexity
baxter CWE-798
2.4
2020-06-26 CVE-2020-9558 Out-of-bounds Read vulnerability in Adobe Bridge
Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds read vulnerability.
local
low complexity
adobe CWE-125
3.3
2020-06-26 CVE-2020-9553 Out-of-bounds Read vulnerability in Adobe Bridge
Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds read vulnerability.
local
low complexity
adobe CWE-125
3.3
2020-06-26 CVE-2020-9626 Out-of-bounds Read vulnerability in Adobe Digital Negative Software Development KIT 1.5
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability.
local
low complexity
adobe CWE-125
3.3
2020-06-25 CVE-2020-3970 Out-of-bounds Read vulnerability in VMWare products
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in the Shader functionality.
local
low complexity
vmware CWE-125
3.8