
Look up vulnerabilities by software, product or CVE number.
| CVE | Published | CVSS | ShadowTrackr CVSS | Summary |
|---|---|---|---|---|
CVE: CVE-2020-1702 | Published 2021-05-27 | CVSS: 3.3 | ShadowTrackr CVSS: 0.2 | Summary: A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, such as Red Hat Enterprise Linux using podman, or OpenShift Container Platform. An attacker can use this flaw to trick a user, with privileges to pull container images, into crashing the process responsible for pulling the image. This flaw affects containers-image versions before 5.2.0. |
CVE: CVE-2020-17029 | Published 2020-11-11 | CVSS: 5.5 | ShadowTrackr CVSS: 1.9 | Summary: Windows Canonical Display Driver Information Disclosure Vulnerability |
CVE: CVE-2020-17028 | Published 2020-11-11 | CVSS: 7.8 | ShadowTrackr CVSS: 4.4 | Summary: Windows Remote Access Elevation of Privilege Vulnerability |
CVE: CVE-2020-17027 | Published 2020-11-11 | CVSS: 7.8 | ShadowTrackr CVSS: 4.4 | Summary: Windows Remote Access Elevation of Privilege Vulnerability |
CVE: CVE-2020-17026 | Published 2020-11-11 | CVSS: 7.8 | ShadowTrackr CVSS: 4.4 | Summary: Windows Remote Access Elevation of Privilege Vulnerability |
CVE: CVE-2020-17024 | Published 2020-11-11 | CVSS: 7.8 | ShadowTrackr CVSS: 4.4 | Summary: Windows Client Side Rendering Print Provider Elevation of Privilege Vulnerability |
CVE: CVE-2020-17025 | Published 2020-11-11 | CVSS: 7.8 | ShadowTrackr CVSS: 4.4 | Summary: Windows Remote Access Elevation of Privilege Vulnerability |
CVE: CVE-2020-17020 | Published 2020-11-11 | CVSS: 3.3 | ShadowTrackr CVSS: 0.2 | Summary: Microsoft Word Security Feature Bypass Vulnerability |
CVE: CVE-2020-17021 | Published 2020-11-11 | CVSS: 5.4 | ShadowTrackr CVSS: 0.4 | Summary: Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
CVE: CVE-2020-17023 | Published 2020-10-16 | CVSS: 7.8 | ShadowTrackr CVSS: 6.2 | Summary: <p>A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into opening a malicious 'package.json' file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p>
<p>To exploit this vulnerability, an attacker would need to convince a target to clone a repository and open it in Visual Studio Code. Attacker-specified code would execute when the target opens the malicious 'package.json' file.</p>
<p>The update address the vulnerability by modifying the way Visual Studio Code handles JSON files.</p> |
CVE: CVE-2020-17022 | Published 2020-10-16 | CVSS: 7.8 | ShadowTrackr CVSS: 6.2 | Summary: <p>A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code.</p>
<p>Exploitation of the vulnerability requires that a program process a specially crafted image file.</p>
<p>The update addresses the vulnerability by correcting how Microsoft Windows Codecs Library handles objects in memory.</p> |