Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2020-10-29 CVE-2020-27650 Missing Encryption of Sensitive Data vulnerability in Synology Diskstation Manager and Skynas Firmware
Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
network
high complexity
synology CWE-311
3.7
2020-10-28 CVE-2020-25374 Insufficient Session Expiration vulnerability in Cyberark Privileged Session Manager 10.9.0.15
CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error popup message after two hours of idle time.
network
high complexity
cyberark CWE-613
2.6
2020-10-27 CVE-2020-9786 Unspecified vulnerability in Apple mac OS X
This issue was addressed with improved checks This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra.
local
low complexity
apple
3.3
2020-10-27 CVE-2019-8857 Improper Input Validation vulnerability in Apple Iphone OS
The issue was addressed with improved validation when an iCloud Link is created.
local
low complexity
apple CWE-20
3.3
2020-10-27 CVE-2019-8856 Unspecified vulnerability in Apple products
An API issue existed in the handling of outgoing phone calls initiated with Siri.
local
low complexity
apple
3.3
2020-10-27 CVE-2019-8842 Classic Buffer Overflow vulnerability in Apple mac OS X
A buffer overflow was addressed with improved bounds checking.
local
low complexity
apple CWE-120
3.3
2020-10-27 CVE-2019-8809 Unspecified vulnerability in Apple products
A validation issue was addressed with improved logic.
local
low complexity
apple
3.3
2020-10-27 CVE-2019-8799 Unspecified vulnerability in Apple products
This issue was resolved by replacing device names with a random identifier.
low complexity
apple
2.4
2020-10-27 CVE-2019-8777 Incorrect Default Permissions vulnerability in Apple mac OS X
A lock screen issue allowed access to contacts on a locked device.
low complexity
apple CWE-276
2.4
2020-10-27 CVE-2019-8732 Incomplete Cleanup vulnerability in Apple Iphone OS
The issue was addressed with improved data deletion.
low complexity
apple CWE-459
2.4