Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2020-02-11 CVE-2020-5829 Out-of-bounds Read vulnerability in Symantec Endpoint Protection Manager
Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.
local
low complexity
symantec CWE-125
3.3
2020-02-11 CVE-2020-5828 Out-of-bounds Read vulnerability in Symantec Endpoint Protection Manager
Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.
local
low complexity
symantec CWE-125
3.3
2020-02-11 CVE-2020-5827 Out-of-bounds Read vulnerability in Symantec Endpoint Protection Manager
Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU2 MP1, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.
local
low complexity
symantec CWE-125
3.3
2020-02-08 CVE-2019-11485 Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users to prevent crash handling.
local
low complexity
apport-project canonical
3.3
2020-02-08 CVE-2019-11483 Sander Bos discovered Apport mishandled crash dumps originating from containers.
local
low complexity
apport-project canonical
3.3
2020-02-06 CVE-2016-1544 Resource Exhaustion vulnerability in multiple products
nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).
local
low complexity
nghttp2 fedoraproject CWE-400
3.3
2020-02-05 CVE-2019-15126 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in multiple products
An issue was discovered on Broadcom Wi-Fi client devices.
high complexity
apple broadcom CWE-367
3.1
2020-02-05 CVE-2019-4616 Missing Encryption of Sensitive Data vulnerability in IBM Cloud Automation Manager 3.2.1.0
IBM Cloud Automation Manager 3.2.1.0 does not set the secure attribute on authorization tokens or session cookies.
low complexity
ibm CWE-311
3.5
2020-02-04 CVE-2019-15622 SQL Injection vulnerability in Nextcloud
Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables when using custom queries.
low complexity
nextcloud CWE-89
2.4
2020-02-04 CVE-2019-15620 Unspecified vulnerability in Nextcloud Talk
Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked them to another shared item via the projects feature.
network
low complexity
nextcloud
2.7