آسیبپذیریهای حیاتی هفته چهارم اردیبهشتماه
این هفته سهشنبههای بهروزرسانی مایکروسافت در ماه مِی را سپری کردیم. دومین سهشنبه هر ماه، شرکت مایکروسافت بهروزرسانیهای لازم را برای محصولات خود منتشر میکند. این آسیبپذیریها مربوط به مهمترین محصولات مایکروسافت یعنی ویندوز، مرورگرهای IE و Edge ، چارچوبهای .NET و SharePoint بودند. امّا علاوه بر محصولات مایکروسافت، آسیبپذیریهای بسیاری با سطوح خطر «بالا» و «حیاتی» در سایر محصولات شرکتهای مهم از جمله IBM، Google Android، Apache، Adobe، Nextcloud و ... شناسایی شده است. به علاوه نرمافزارهایی نظیر Symantec، McAfee و Avira و کرنل لینوکس نیز چندین آسیبپذیری خطرناک و حیاتی داشتند.
لیست این آسیبپذیریها به همراه لینک وصلهها و بهروزرسانیهای ارائهشده در جدول زیر آمده است.
رفع آسیبپذیری |
نوع آسیبپذیری |
محصول آسیبپذیر |
شناسه آسیبپذیری |
Remote Code Execution |
Actionpack_page-caching Gem Web Server |
CVE-2020-8159 |
|
DoS |
Adobe Acrobat Reader |
CVE-2020-9611 |
|
Memory Corruption |
Adobe Acrobat Reader Heap-based |
CVE-2020-9612 |
|
Information Disclosure |
Adobe Acrobat Reader |
CVE-2020-9593 |
|
Information Disclosure |
Adobe Acrobat Reader |
CVE-2020-9595 |
|
Information Disclosure |
Adobe Acrobat Reader |
CVE-2020-9598 |
|
Memory Corruption |
Adobe Acrobat Reader |
CVE-2020-9604 |
|
Memory Corruption |
Adobe Acrobat Reader |
CVE-2020-9605 |
|
DoS |
Adobe Acrobat Reader NULL Pointer Dereference |
CVE-2020-9610 |
|
Information Disclosure |
Adobe Acrobat Reader Out-of-Bounds |
CVE-2020-9599 |
|
Information Disclosure |
Adobe Acrobat Reader Out-of-Bounds |
CVE-2020-9600 |
|
Information Disclosure |
Adobe Acrobat Reader Out-of-Bounds |
CVE-2020-9601 |
|
Information Disclosure |
Adobe Acrobat Reader Out-of-Bounds |
CVE-2020-9602 |
|
Information Disclosure |
Adobe Acrobat Reader Out-of-Bounds |
CVE-2020-9603 |
|
Information Disclosure |
Adobe Acrobat Reader Out-of-Bounds |
CVE-2020-9608 |
|
Information Disclosure |
Adobe Acrobat Reader Out-of-Bounds |
CVE-2020-9609 |
|
Memory Corruption |
Adobe Acrobat Reader Out-of-Bounds |
CVE-2020-9594 |
|
Memory Corruption |
Adobe Acrobat Reader Out-of-Bounds |
CVE-2020-9597 |
|
Privilege Escalation |
Adobe Acrobat Reader |
CVE-2020-9592 |
|
Privilege Escalation |
Adobe Acrobat Reader |
CVE-2020-9596 |
|
Privilege Escalation |
Adobe Acrobat Reader |
CVE-2020-9613 |
|
Privilege Escalation |
Adobe Acrobat Reader |
CVE-2020-9614 |
|
Race Condition |
Adobe Acrobat Reader |
CVE-2020-9615 |
|
Memory Corruption |
Adobe Acrobat Reader Use-After-Free |
CVE-2020-9606 |
|
Memory Corruption |
Adobe Acrobat Reader Use-After-Free |
CVE-2020-9607 |
|
Not Defined |
Directory Traversal |
Advantech WebAccess Node |
CVE-2020-12026 |
Not Defined |
Directory Traversal |
Advantech WebAccess Node |
CVE-2020-12010 |
Not Defined |
Directory Traversal |
Advantech WebAccess Node |
CVE-2020-12006 |
Not Defined |
Memory Corruption |
Advantech WebAccess Node Heap-based |
CVE-2020-10638 |
Not Defined |
Privilege Escalation |
Advantech WebAccess Node Injection |
CVE-2020-12022 |
Not Defined |
Memory Corruption |
Advantech WebAccess Node Out-of-Bounds |
CVE-2020-12018 |
Not Defined |
SQL Injection |
Advantech WebAccess Node |
CVE-2020-12014 |
Not Defined |
Memory Corruption |
Advantech WebAccess Node Stack-based |
CVE-2020-12002 |
Not Defined |
XSS |
ALSong DOM-Based |
CVE-2020-7809 |
Information Disclosure |
Ansible Engine/Ansible Tower Decryption tmp |
CVE-2020-10685 |
|
Not Defined |
Privilege Escalation |
Ansible Engine/Ansible Tower fuse Filesystem Temporary |
CVE-2020-10744 |
Not Defined |
XSS |
Apache ActiveMQ Webconsole Admin GUI |
CVE-2020-1941 |
Not Defined |
Privilege Escalation |
Apache ant Temp Directory Code Injection |
CVE-2020-1945 |
Unknown Vulnerability |
Apache Camel JMX |
CVE-2020-11971 |
|
Privilege Escalation |
Apache Camel Netty Deserialization |
CVE-2020-11973 |
|
Privilege Escalation |
Apache Camel RabbitMQ Deserialization |
CVE-2020-11972 |
|
Command Injection |
Apache CloudStack baremetal |
CVE-2019-17562 |
|
Not Defined |
Privilege Escalation |
Apache Flink JMXRMI Registry Man-in-the-Middle |
CVE-2020-1960 |
XML External Entity |
Apache log4net Configuration File |
CVE-2018-1285 |
|
Not Defined |
Directory Traversal |
Apache RocketMQ Broker |
CVE-2019-17572 |
Not Defined |
Information Disclosure |
Avira Free Antivirus Avira.PWM.NativeMessaging.exe |
CVE-2020-12680 |
DoS |
BitDefender Engine Sample Scanner cevakrnl.rv0 |
CVE-2020-8100 |
|
Not Defined |
Information Disclosure |
Bond JetSelect Developer Tools Credentials |
CVE-2019-13023 |
Not Defined |
Weak Encryption |
Bond JetSelect ENCtool.jar |
CVE-2019-13022 |
Not Defined |
Information Disclosure |
Bond JetSelect sfc-general-properties |
CVE-2019-13021 |
Not Defined |
SQL Injection |
Chop Slider Plugin index.php |
CVE-2020-11530 |
Not Defined |
Memory Corruption |
ClamAV Antivirus ARJ Archive Parser Heap-based |
CVE-2020-3327 |
Not Defined |
Memory Corruption |
ClamAV Antivirus PDF Archive Parser Stack-based |
CVE-2020-3341 |
Privilege Escalation |
CODESYS Development System |
CVE-2020-12068 |
|
Not Defined |
DoS |
COVIDSafe App Bluetooth Advertisement Crash |
CVE-2020-12717 |
Privilege Escalation |
cPanel Account Backup |
CVE-2020-12785 |
|
DoS |
cPanel Mail Log |
CVE-2020-12784 |
|
Not Defined |
Weak Authentication |
Dahua Device Login Mode |
CVE-2019-9682 |
Not Defined |
Weak Authentication |
Dahua Products Session |
CVE-2020-9502 |
Not Defined |
Information Disclosure |
Dahua Web P2P Key |
CVE-2020-9501 |
Not Defined |
Privilege Escalation |
direct_mail Extension Access Control |
CVE-2020-12698 |
Not Defined |
DoS |
direct_mail Extension |
CVE-2020-12697 |
Not Defined |
Information Disclosure |
direct_mail Extension Newsletter Subscribe |
CVE-2020-12700 |
Not Defined |
Open Redirect |
direct_mail Extension |
CVE-2020-12699 |
Workaround |
Privilege Escalation |
D-Link DAP-1360 Telnet Service |
CVE-2019-18666 |
Not Defined |
Weak Authentication |
DomainMod Password Reset reset.php |
CVE-2020-12735 |
Memory Corruption |
FreeBSD cryptodev Kernel Memory |
CVE-2019-15879 |
|
Information Disclosure |
FreeBSD FTP Packet |
CVE-2020-7455 |
|
DoS |
FreeBSD Kernel Panic |
CVE-2019-15880 |
|
Memory Corruption |
FreeBSD Out-of-Bounds |
CVE-2020-7454 |
|
Memory Corruption |
FreeBSD SCTP Use-After-Free |
CVE-2019-15878 |
|
Not Defined |
Information Disclosure |
FreeRDP bitmap.c |
CVE-2020-11525 |
Not Defined |
Information Disclosure |
FreeRDP gdi.c |
CVE-2020-11522 |
Not Defined |
Memory Corruption |
FreeRDP interleaved.c |
CVE-2020-11524 |
Not Defined |
Memory Corruption |
FreeRDP planar.c |
CVE-2020-11521 |
Not Defined |
Memory Corruption |
FreeRDP region.c |
CVE-2020-11523 |
Not Defined |
Information Disclosure |
FreeRDP update.c |
CVE-2020-11526 |
Not Defined |
Privilege Escalation |
Gazie setup.php |
CVE-2020-12743 |
Not Defined |
SQL Injection |
Gnuteca action=main:search:simpleSearch |
CVE-2020-12766 |
Not Defined |
Directory Traversal |
Gnuteca file.php |
CVE-2020-12764 |
Memory Corruption |
Google Android a2dp_aac_decoder.cc a2dp_aac_decoder_cleanup |
CVE-2020-0103 |
|
Privilege Escalation |
Google Android ActivityStack.java navigateUpToLocked |
CVE-2020-0098 |
|
Privilege Escalation |
Google Android ActivityStartController.java startActivities |
CVE-2020-0096 |
|
Memory Corruption |
Google Android Airbrush FW |
CVE-2020-0221 |
|
Privilege Escalation |
Google Android Email |
CVE-2020-0090 |
|
Information Disclosure |
Google Android exif-data.c exif_data_save_data_entry |
CVE-2020-0093 |
|
Memory Corruption |
Google Android ExifUtils.cpp setImageWidth |
CVE-2020-0094 |
|
Memory Corruption |
Google Android gatt_server.cc SendResponse |
CVE-2020-0102 |
|
Information Disclosure |
Google Android ICrypto.cpp onTransact |
CVE-2020-0101 |
|
Information Disclosure |
Google Android IHDCP.cpp onTransact |
CVE-2020-0100 |
|
Information Disclosure |
Google Android KeyguardStateMonitor.java onShowingStateChanged |
CVE-2020-0104 |
|
Privilege Escalation |
Google Android mnld |
CVE-2020-0091 |
|
Memory Corruption |
Google Android msm-cirrus-playback.c crus_afe_callback |
CVE-2020-0220 |
|
Information Disclosure |
Google Android NotificationStackScrollLayout.java setHideSensitive |
CVE-2020-0092 |
|
Privilege Escalation |
Google Android PackageManagerService.java |
CVE-2020-0097 |
|
Privilege Escalation |
Google Android Permission Check key_store_service.cpp onKeyguardVisibilityChanged |
CVE-2020-0105 |
|
Privilege Escalation |
Google Android Permission Check NotificationManagerService.java simulatePackageSuspendBroadcast |
CVE-2020-0109 |
|
Privilege Escalation |
Google Android |
CVE-2020-0064 |
|
Memory Corruption |
Google Android psi.c psi_write |
CVE-2020-0110 |
|
Privilege Escalation |
Google Android Receiver |
CVE-2020-0065 |
|
Information Disclosure |
Google Android SDK Version Check PhoneInterfaceManager.java getCellLocation |
CVE-2020-0106 |
|
Privilege Escalation |
Google Android SettingsBaseActivity.java onCreate |
CVE-2020-0024 |
|
Not Defined |
Privilege Escalation |
Groupfolders App Access Control |
CVE-2020-8153 |
Weak Authentication |
Huawei P20 |
CVE-2020-9073 |
|
Information Disclosure |
Huawei View 20/Honor 20/Honor 20 Pro/Honor Magic2 Out-of-Bounds |
CVE-2020-1808 |
|
Not Defined |
Memory Corruption |
IBM i2 Intelligent Analyis Platform |
CVE-2020-4468 |
Not Defined |
Memory Corruption |
IBM i2 Intelligent Analyis Platform |
CVE-2020-4467 |
Not Defined |
Memory Corruption |
IBM i2 Intelligent Analyis Platform |
CVE-2020-4422 |
Not Defined |
Memory Corruption |
IBM i2 Intelligent Analyis Platform |
CVE-2020-4343 |
Not Defined |
Memory Corruption |
IBM i2 Intelligent Analyis Platform |
CVE-2020-4288 |
Not Defined |
Memory Corruption |
IBM i2 Intelligent Analyis Platform |
CVE-2020-4287 |
Not Defined |
Memory Corruption |
IBM i2 Intelligent Analyis Platform |
CVE-2020-4285 |
Not Defined |
Memory Corruption |
IBM i2 Intelligent Analyis Platform |
CVE-2020-4266 |
Not Defined |
Memory Corruption |
IBM i2 Intelligent Analyis Platform |
CVE-2020-4265 |
Not Defined |
Memory Corruption |
IBM i2 Intelligent Analyis Platform |
CVE-2020-4264 |
Not Defined |
Memory Corruption |
IBM i2 Intelligent Analyis Platform |
CVE-2020-4263 |
Not Defined |
Memory Corruption |
IBM i2 Intelligent Analyis Platform |
CVE-2020-4262 |
Not Defined |
Memory Corruption |
IBM i2 Intelligent Analyis Platform |
CVE-2020-4261 |
Not Defined |
Memory Corruption |
IBM i2 Intelligent Analyis Platform |
CVE-2020-4258 |
Not Defined |
Memory Corruption |
IBM i2 Intelligent Analyis Platform |
CVE-2020-4257 |
Not Defined |
Information Disclosure |
IBM Sterling B2B Integrator Standard Edition |
CVE-2020-4299 |
Not Defined |
Information Disclosure |
IBM Sterling B2B Integrator Standard Edition Web Page Cache |
CVE-2020-4312 |
Not Defined |
Privilege Escalation |
IBM Sterling File Gateway |
CVE-2020-4259 |
Not Defined |
Information Disclosure |
IBM UrbanCode Deploy HSTS |
CVE-2019-4667 |
Not Defined |
Server-Side Request Forgery |
IBM WebSphere Application Server |
CVE-2020-4365 |
Memory Corruption |
Iconimlib2 Color Map loader_ico.c |
CVE-2020-12761 |
|
Memory Corruption |
iproute2 ipnetns.c get_netnsid_from_name |
CVE-2019-20795 |
|
Privilege Escalation |
JAL Information Technology Pallet Control Access Control |
CVE-2020-5538 |
|
Directory Traversal |
Jooby |
CVE-2020-7647 |
|
Not Defined |
Memory Corruption |
json-c JSON File printbuf_memappend |
CVE-2020-12762 |
Not Defined |
Weak Authentication |
KDE kio-extras fish.cpp establishConnection |
CVE-2020-12755 |
Not Defined |
Privilege Escalation |
KeyCloak Admin Console |
CVE-2019-10170 |
Privilege Escalation |
KeyCloak Deserialization |
CVE-2020-1714 |
|
Information Disclosure |
KeyCloak HttpMethod |
CVE-2020-1698 |
|
Information Disclosure |
KeyCloak |
CVE-2020-1724 |
|
Weak Authentication |
KeyCloak TLS Hostname Verification Man-in-the-Middle |
CVE-2020-1758 |
|
Not Defined |
Privilege Escalation |
KeyCloak User-Managed Access Interface |
CVE-2019-10169 |
Not Defined |
Remote Code Execution |
LG Mobile Devices Bootloader |
CVE-2020-12753 |
Not Defined |
Privilege Escalation |
LG Mobile Devices Window System Service |
CVE-2020-12754 |
Not Defined |
DoS |
libEMF |
CVE-2020-11864 |
Not Defined |
DoS |
libEMF |
CVE-2020-11863 |
Not Defined |
Memory Corruption |
libEMF Out-of-Bounds |
CVE-2020-11865 |
Not Defined |
Memory Corruption |
libEMF Use-After-Free |
CVE-2020-11866 |
Not Defined |
DoS |
libexif exif-entry.c exif_entry_get_value |
CVE-2020-12767 |
Not Defined |
DoS |
Linux Kernel btree.c btree_gc_coalesce |
CVE-2020-12771 |
Privilege Escalation |
Linux Kernel Fix CVE-2019-11599 get_task_mm |
CVE-2019-14898 |
|
Not Defined |
DoS |
Linux Kernel fuse Filesystem Resource Exhaustion |
CVE-2019-20794 |
Memory Corruption |
Linux Kernel ptp Device ptpX |
CVE-2020-10690 |
|
Privilege Escalation |
Linux Kernel sg_write |
CVE-2020-12770 |
|
DoS |
Linux Kernel spi-dw.c dw_spi_transfer_one |
CVE-2020-12769 |
|
DoS |
Linux Kernel svm.c svm_cpu_uninit |
CVE-2020-12768 |
|
Not Defined |
Privilege Escalation |
Linux Kernel VFIO PCI Driver |
CVE-2020-12888 |
Privilege Escalation |
McAfee Active Response |
CVE-2020-7291 |
|
Privilege Escalation |
McAfee Active Response |
CVE-2020-7290 |
|
Privilege Escalation |
McAfee Active Response |
CVE-2020-7289 |
|
Privilege Escalation |
McAfee Endpoint Security Symbolic Link |
CVE-2020-7265 |
|
Privilege Escalation |
McAfee Endpoint Security Symbolic Links |
CVE-2020-7264 |
|
Privilege Escalation |
McAfee Exploit Detection and Response |
CVE-2020-7288 |
|
Privilege Escalation |
McAfee Exploit Detection and Response |
CVE-2020-7287 |
|
Privilege Escalation |
McAfee Exploit Detection and Response |
CVE-2020-7286 |
|
Privilege Escalation |
McAfee MVision Endpoint |
CVE-2020-7285 |
|
Privilege Escalation |
McAfee VirusScan Enterprise Symbolic Link |
CVE-2020-7267 |
|
Privilege Escalation |
McAfee VirusScan Enterprise Symbolic Link |
CVE-2020-7266 |
|
DoS |
Microsoft .NET Core/.NET Framework |
CVE-2020-1108 |
|
Privilege Escalation |
Microsoft .NET Framework |
CVE-2020-1066 |
|
XSS |
Microsoft Dynamics 365 on-premises |
CVE-2020-1063 |
|
Privilege Escalation |
Microsoft Edge Cross-Origin |
CVE-2020-1056 |
|
Open Redirect |
Microsoft Edge |
CVE-2020-1059 |
|
Memory Corruption |
Microsoft Edge PDF |
CVE-2020-1096 |
|
Memory Corruption |
Microsoft Edge/ChakraCore Chakra Scripting Engine |
CVE-2020-1037 |
|
Memory Corruption |
Microsoft Edge/ChakraCore Scripting Engine |
CVE-2020-1065 |
|
Memory Corruption |
Microsoft Excel |
CVE-2020-0901 |
|
Memory Corruption |
Microsoft Internet Explorer |
CVE-2020-1092 |
|
Memory Corruption |
Microsoft Internet Explorer |
CVE-2020-1062 |
|
Privilege Escalation |
Microsoft Internet Explorer MSHTML Engine |
CVE-2020-1064 |
|
Memory Corruption |
Microsoft Internet Explorer VBScript |
CVE-2020-1060 |
|
Memory Corruption |
Microsoft Internet Explorer VBScript |
CVE-2020-1058 |
|
Memory Corruption |
Microsoft Internet Explorer VBScript |
CVE-2020-1035 |
|
Memory Corruption |
Microsoft Internet Explorer VBScript |
CVE-2020-1093 |
|
Privilege Escalation |
Microsoft Power BI Report Server |
CVE-2020-1173 |
|
Privilege Escalation |
Microsoft SharePoint Enterprise Server ASP.Net Web Control |
CVE-2020-1069 |
|
CSRF |
Microsoft SharePoint Enterprise Server |
CVE-2020-1103 |
|
XSS |
Microsoft SharePoint Enterprise Server |
CVE-2020-1107 |
|
XSS |
Microsoft SharePoint Enterprise Server |
CVE-2020-1106 |
|
XSS |
Microsoft SharePoint Enterprise Server |
CVE-2020-1105 |
|
XSS |
Microsoft SharePoint Enterprise Server |
CVE-2020-1104 |
|
XSS |
Microsoft SharePoint Enterprise Server |
CVE-2020-1101 |
|
XSS |
Microsoft SharePoint Enterprise Server |
CVE-2020-1100 |
|
XSS |
Microsoft SharePoint Enterprise Server |
CVE-2020-1099 |
|
Privilege Escalation |
Microsoft SharePoint Enterprise Server Source Markup |
CVE-2020-1102 |
|
Privilege Escalation |
Microsoft SharePoint Enterprise Server Source Markup |
CVE-2020-1024 |
|
Privilege Escalation |
Microsoft SharePoint Enterprise Server Source Markup |
CVE-2020-1023 |
|
Privilege Escalation |
Microsoft Visual Studio Code Python Extension |
CVE-2020-1171 |
|
Privilege Escalation |
Microsoft Visual Studio Code Python Extension |
CVE-2020-1192 |
|
DoS |
Microsoft Visual Studio/ASP.NET Core |
CVE-2020-1161 |
|
XSS |
Microsoft Windows Active Directory Federation Services |
CVE-2020-1055 |
|
Privilege Escalation |
Microsoft Windows Background Intelligent Transfer Service File Upload |
CVE-2020-1112 |
|
DoS |
Microsoft Windows Block Level Backup Engine Service |
CVE-2020-1010 |
|
Privilege Escalation |
Microsoft Windows Clipboard |
CVE-2020-1111 |
|
Privilege Escalation |
Microsoft Windows Clipboard Service |
CVE-2020-1166 |
|
Privilege Escalation |
Microsoft Windows Clipboard Service |
CVE-2020-1165 |
|
Privilege Escalation |
Microsoft Windows Clipboard Service |
CVE-2020-1121 |
|
Memory Corruption |
Microsoft Windows Color Management ICM32.dll |
CVE-2020-1117 |
|
Privilege Escalation |
Microsoft Windows Common Log File System Driver |
CVE-2020-1154 |
|
DoS |
Microsoft Windows Connected User Experiences and Telemetry Service |
CVE-2020-1123 |
|
DoS |
Microsoft Windows Connected User Experiences and Telemetry Service |
CVE-2020-1084 |
|
Information Disclosure |
Microsoft Windows CSRSS |
CVE-2020-1116 |
|
DoS |
Microsoft Windows |
CVE-2020-1076 |
|
Memory Corruption |
Microsoft Windows DirectX |
CVE-2020-1140 |
|
Privilege Escalation |
Microsoft Windows Error Reporting Manager |
CVE-2020-1132 |
|
Privilege Escalation |
Microsoft Windows Error Reporting |
CVE-2020-1088 |
|
Privilege Escalation |
Microsoft Windows Error Reporting |
CVE-2020-1082 |
|
Privilege Escalation |
Microsoft Windows Error Reporting |
CVE-2020-1021 |
|
Information Disclosure |
Microsoft Windows GDI |
CVE-2020-1179 |
|
Information Disclosure |
Microsoft Windows GDI |
CVE-2020-1145 |
|
Information Disclosure |
Microsoft Windows GDI |
CVE-2020-1141 |
|
Information Disclosure |
Microsoft Windows GDI |
CVE-2020-0963 |
|
Memory Corruption |
Microsoft Windows GDI |
CVE-2020-1142 |
|
Memory Corruption |
Microsoft Windows Graphics Component |
CVE-2020-1135 |
|
Memory Corruption |
Microsoft Windows Graphics Component |
CVE-2020-1153 |
|
DoS |
Microsoft Windows Hyper-V |
CVE-2020-0909 |
|
Information Disclosure |
Microsoft Windows |
CVE-2020-1072 |
|
Memory Corruption |
Microsoft Windows JET Database Engine |
CVE-2020-1176 |
|
Memory Corruption |
Microsoft Windows JET Database Engine |
CVE-2020-1175 |
|
Memory Corruption |
Microsoft Windows JET Database Engine |
CVE-2020-1174 |
|
Memory Corruption |
Microsoft Windows JET Database Engine |
CVE-2020-1051 |
|
Memory Corruption |
Microsoft Windows Kernel |
CVE-2020-1114 |
|
Memory Corruption |
Microsoft Windows Kernel |
CVE-2020-1087 |
|
Memory Corruption |
Microsoft Windows Media Foundation |
CVE-2020-1150 |
|
Memory Corruption |
Microsoft Windows Media Foundation |
CVE-2020-1136 |
|
Memory Corruption |
Microsoft Windows Media Foundation |
CVE-2020-1126 |
|
Memory Corruption |
Microsoft Windows Media Foundation |
CVE-2020-1028 |
|
Privilege Escalation |
Microsoft Windows Media Service |
CVE-2020-1068 |
|
Memory Corruption |
Microsoft Windows |
CVE-2020-1079 |
|
Memory Corruption |
Microsoft Windows |
CVE-2020-1067 |
|
Privilege Escalation |
Microsoft Windows Print Spooler |
CVE-2020-1070 |
|
Privilege Escalation |
Microsoft Windows Print Spooler |
CVE-2020-1048 |
|
Privilege Escalation |
Microsoft Windows Printer Service |
CVE-2020-1081 |
|
Memory Corruption |
Microsoft Windows Push Notification Service |
CVE-2020-1137 |
|
Privilege Escalation |
Microsoft Windows Remote Access Common Dialog |
CVE-2020-1071 |
|
Memory Corruption |
Microsoft Windows Script Runtime |
CVE-2020-1061 |
|
Memory Corruption |
Microsoft Windows State Repository Service |
CVE-2020-1191 |
|
Memory Corruption |
Microsoft Windows State Repository Service |
CVE-2020-1190 |
|
Memory Corruption |
Microsoft Windows State Repository Service |
CVE-2020-1189 |
|
Memory Corruption |
Microsoft Windows State Repository Service |
CVE-2020-1188 |
|
Memory Corruption |
Microsoft Windows State Repository Service |
CVE-2020-1187 |
|
Memory Corruption |
Microsoft Windows State Repository Service |
CVE-2020-1186 |
|
Memory Corruption |
Microsoft Windows State Repository Service |
CVE-2020-1185 |
|
Memory Corruption |
Microsoft Windows State Repository Service |
CVE-2020-1184 |
|
Memory Corruption |
Microsoft Windows State Repository Service |
CVE-2020-1144 |
|
Memory Corruption |
Microsoft Windows State Repository Service |
CVE-2020-1134 |
|
Memory Corruption |
Microsoft Windows State Repository Service |
CVE-2020-1131 |
|
Memory Corruption |
Microsoft Windows State Repository Service |
CVE-2020-1124 |
|
Privilege Escalation |
Microsoft Windows Storage Service |
CVE-2020-1138 |
|
Information Disclosure |
Microsoft Windows Subsystem for Linux |
CVE-2020-1075 |
|
Privilege Escalation |
Microsoft Windows Task Scheduler |
CVE-2020-1113 |
|
DoS |
Microsoft Windows TLS |
CVE-2020-1118 |
|
Memory Corruption |
Microsoft Windows Update Stack |
CVE-2020-1110 |
|
Memory Corruption |
Microsoft Windows Update Stack |
CVE-2020-1109 |
|
Memory Corruption |
Microsoft Windows Win32k |
CVE-2020-1143 |
|
Memory Corruption |
Microsoft Windows Win32k |
CVE-2020-1054 |
|
Privilege Escalation |
Microsoft Windows Windows Installer |
CVE-2020-1078 |
|
Memory Corruption |
Microsoft Windows Windows Runtime |
CVE-2020-1164 |
|
Memory Corruption |
Microsoft Windows Windows Runtime |
CVE-2020-1158 |
|
Memory Corruption |
Microsoft Windows Windows Runtime |
CVE-2020-1157 |
|
Memory Corruption |
Microsoft Windows Windows Runtime |
CVE-2020-1156 |
|
Memory Corruption |
Microsoft Windows Windows Runtime |
CVE-2020-1155 |
|
Memory Corruption |
Microsoft Windows Windows Runtime |
CVE-2020-1151 |
|
Memory Corruption |
Microsoft Windows Windows Runtime |
CVE-2020-1139 |
|
Memory Corruption |
Microsoft Windows Windows Runtime |
CVE-2020-1125 |
|
Memory Corruption |
Microsoft Windows Windows Runtime |
CVE-2020-1090 |
|
Memory Corruption |
Microsoft Windows Windows Runtime |
CVE-2020-1086 |
|
Privilege Escalation |
Microsoft Windows Windows Runtime |
CVE-2020-1149 |
|
Privilege Escalation |
Microsoft Windows Windows Runtime |
CVE-2020-1077 |
|
Not Defined |
Information Disclosure |
MongoDB Ops Manager Log |
CVE-2019-2388 |
Not Defined |
CSRF |
Movable Type |
CVE-2020-5576 |
Not Defined |
XSS |
Movable Type |
CVE-2020-5575 |
Not Defined |
XSS |
Movable Type |
CVE-2020-5574 |
Not Defined |
Privilege Escalation |
Movable Type File Upload |
CVE-2020-5577 |
Not Defined |
DoS |
NetApp Service Processor/Baseboard Management Controller |
CVE-2019-5500 |
Not Defined |
Weak Authentication |
NextCloud Mail TLS Host Man-in-the-Middle |
CVE-2020-8156 |
Not Defined |
DoS |
Nextcloud Server Endpoint |
CVE-2020-8154 |
Not Defined |
XSS |
Nextcloud Server PDF Viewer |
CVE-2020-8155 |
Not Defined |
Privilege Escalation |
nginx Request Smuggling |
CVE-2020-12440 |
Remote Code Execution |
OpenNMS Horizon/Meridian ActiveMQ Channel |
CVE-2020-12760 |
|
XSS |
openSUSE open-build-service Web Page Generation |
CVE-2020-8020 |
|
Not Defined |
Privilege Escalation |
Opto 22 SoftPAC DLL |
CVE-2020-10616 |
Not Defined |
Privilege Escalation |
Opto 22 SoftPAC |
CVE-2020-12042 |
Workaround |
Privilege Escalation |
Opto 22 SoftPAC Service Port 22000 |
CVE-2020-10612 |
Not Defined |
Privilege Escalation |
Opto 22 SoftPAC Signature |
CVE-2020-12046 |
Not Defined |
Weak Authentication |
Opto 22 SoftPAC |
CVE-2020-10620 |
Not Defined |
Information Disclosure |
Oracle iPlanet Web Server Administration Console |
CVE-2020-9315 |
Not Defined |
Privilege Escalation |
Oracle iPlanet Web Server Administration Console Injection |
CVE-2020-9314 |
Information Disclosure |
Palo Alto GlobalProtect App Diagnostic Log PanGPS.log |
CVE-2020-2004 |
|
Weak Authentication |
Palo Alto PAN-OS Authentication Daemon |
CVE-2020-2002 |
|
Weak Encryption |
Palo Alto PAN-OS Cleartext |
CVE-2020-2013 |
|
DoS |
Palo Alto PAN-OS Command |
CVE-2020-2003 |
|
DoS |
Palo Alto PAN-OS Configuration Daemon Crash |
CVE-2020-2011 |
|
XSS |
Palo Alto PAN-OS GlobalProtect Clientless VPN |
CVE-2020-2005 |
|
Open Redirect |
Palo Alto PAN-OS GlobalProtect Gateway |
CVE-2020-1997 |
|
Weak Authentication |
Palo Alto PAN-OS GlobalProtect Portal Session Fixation |
CVE-2020-1993 |
|
Privilege Escalation Command Injection |
Palo Alto PAN-OS Management Interface OS |
CVE-2020-2010 |
|
Privilege Escalation |
Palo Alto PAN-OS Management Interface |
CVE-2020-2001 |
|
XML External Entity |
Palo Alto PAN-OS Management Interface |
CVE-2020-2012 |
|
Privilege Escalation |
Palo Alto PAN-OS Management Server Injection |
CVE-2020-1996 |
|
Memory Corruption |
Palo Alto PAN-OS Management Server |
CVE-2020-2015 |
|
Privilege Escalation Command Injection |
Palo Alto PAN-OS Management Server OS |
CVE-2020-2014 |
|
Privilege Escalation Command Injection |
Palo Alto PAN-OS Management Server OS |
CVE-2020-2007 |
|
Memory Corruption |
Palo Alto PAN-OS Management Server Stack-based |
CVE-2020-2006 |
|
XSS |
Palo Alto PAN-OS Management Web Interface DOM-Based |
CVE-2020-2017 |
|
Privilege Escalation Command Injection |
Palo Alto PAN-OS OS |
CVE-2020-2008 |
|
Weak Authentication |
Palo Alto PAN-OS Proxy Service |
CVE-2020-2018 |
|
DoS |
Palo Alto PAN-OS rasmgr Daemon NULL Pointer Dereference |
CVE-2020-1995 |
|
Privilege Escalation |
Palo Alto PAN-OS SAML Permission |
CVE-2020-1998 |
|
Remote Code Execution |
Palo Alto PAN-OS SD WAN |
CVE-2020-2009 |
|
Not Defined |
Privilege Escalation |
Palo Alto PAN-OS Temp Directory |
CVE-2020-2016 |
Privilege Escalation |
Palo Alto PAN-OS Temp File |
CVE-2020-1994 |
|
Not Defined |
XSS |
php-fusion Preview Comment comments.php |
CVE-2020-12718 |
Not Defined |
Remote Code Execution |
Pi-Hole Gravity Updater gravity.sh gravity_DownloadBlocklistFromUrl |
CVE-2020-11108 |
Memory Corruption |
Ping Identity PingID SSH Authenticating Endpoint Heap-based |
CVE-2020-10654 |
|
Not Defined |
Spoofing |
Samsung Galaxy S8/Galaxy S8+/Galaxy Note 8 Bluetooth Pseudo Random Number Generator |
CVE-2020-6616 |
Not Defined |
Memory Corruption |
Samsung Mobile Devices Bootloader Heap-based |
CVE-2020-12747 |
Not Defined |
Memory Corruption |
Samsung Mobile Devices Exynos Chipset |
CVE-2020-12749 |
Not Defined |
Privilege Escalation |
Samsung Mobile Devices Factory Reset Protection |
CVE-2020-12750 |
Not Defined |
Information Disclosure |
Samsung Mobile Devices Gatekeeper Trustlet Bruteforce |
CVE-2020-12752 |
Not Defined |
Weak Authentication |
Samsung Mobile Devices Protection Mechanism |
CVE-2020-12745 |
Not Defined |
Memory Corruption |
Samsung Mobile Devices Quram Image Codec Library |
CVE-2020-12751 |
Not Defined |
Weak Authentication |
Samsung Mobile Devices Screenlock |
CVE-2020-12748 |
Not Defined |
Memory Corruption |
Samsung Mobile Devices Secure Bootloader Heap-based |
CVE-2020-12746 |
Not Defined |
Information Disclosure |
SAP Adaptive Server Enterprise |
CVE-2020-6259 |
Not Defined |
Information Disclosure |
SAP Adaptive Server Enterprise |
CVE-2020-6252 |
Not Defined |
SQL Injection |
SAP Adaptive Server Enterprise Web Services |
CVE-2020-6253 |
Not Defined |
Privilege Escalation |
SAP Application Server ABAP Data Download Service Code Injection |
CVE-2020-6262 |
Not Defined |
XSS |
SAP Business Intelligence Platform |
CVE-2020-6257 |
Not Defined |
Privilege Escalation |
SAP Business Intelligence Platform Error |
CVE-2020-6251 |
Not Defined |
XSS |
SAP Enterprise Threat Detection Error Message Reflected |
CVE-2020-6254 |
Not Defined |
Information Disclosure |
SAP Identity Management |
CVE-2020-6258 |
Not Defined |
Privilege Escalation |
SAP Master Data Governance |
CVE-2020-6256 |
Memory Corruption |
SecureCRT Integer Overflow |
CVE-2020-12651 |
|
Privilege Escalation |
SEOmatic Plugin URL DynamicMeta.php |
CVE-2020-12790 |
|
Unknown Vulnerability |
Shopizer Backend |
CVE-2020-11006 |
|
Directory Traversal |
simple-file-list Plugin |
CVE-2020-12832 |
|
Weak Encryption |
Spring Security CBC Mode |
CVE-2020-5408 |
|
Privilege Escalation |
Spring Security Signature |
CVE-2020-5407 |
|
Not Defined |
CSRF |
Subrion CMS |
CVE-2019-20390 |
Not Defined |
XSS |
Subrion CMS General Settings Page general |
CVE-2019-20389 |
XSS |
SVG Sanitizer Extension Markup |
CVE-2020-11070 |
|
DoS |
SwiftNIO Extras |
CVE-2020-9840 |
|
Privilege Escalation |
Symantec Endpoint Protection ACL |
CVE-2020-5836 |
|
Privilege Escalation |
Symantec Endpoint Protection Log File |
CVE-2020-5837 |
|
Privilege Escalation |
Symantec Endpoint Protection Manager Client Remote Deployment |
CVE-2020-5835 |
|
Directory Traversal |
Symantec Endpoint Protection Manager |
CVE-2020-5834 |
|
Memory Corruption |
Symantec Endpoint Protection Manager Out-of-Bounds |
CVE-2020-5833 |
|
XSS |
Symantec IT Analytics |
CVE-2020-5838 |
|
Not Defined |
Memory Corruption |
tcpreplay tcprewrite get.c get_ipv6_next() |
CVE-2020-12740 |
Memory Corruption |
transmission Torrent File variant.c |
CVE-2018-10756 |
|
Not Defined |
Memory Corruption |
TRENDnet TV-IP512WN sbin |
CVE-2020-12763 |
Not Defined |
Privilege Escalation |
TylerTech Eagle |
CVE-2019-16112 |
CSRF |
TYPO3 CMS Backend User Interface |
CVE-2020-11069 |
|
Privilege Escalation |
TYPO3 CMS Deserialization |
CVE-2020-11067 |
|
Privilege Escalation |
TYPO3 CMS unserialize() |
CVE-2020-11066 |
|
XSS |
TYPO3 HTML Placeholder Attribute |
CVE-2020-11064 |
|
XSS |
TYPO3 Link Tag |
CVE-2020-11065 |
|
Not Defined |
Information Disclosure |
TYPO3 Password Reset Email |
CVE-2020-11063 |
Privilege Escalation |
vBulletin Access Control |
CVE-2020-12720 |
|
Information Disclosure |
Veritas APTARE |
CVE-2020-12877 |
|
Information Disclosure |
Veritas APTARE |
CVE-2020-12876 |
|
Information Disclosure |
Veritas APTARE |
CVE-2020-12875 |
|
Weak Authentication |
Veritas APTARE |
CVE-2020-12874 |
|
Memory Corruption |
VideoLAN VLC Media Player sdl_image.c DecodeBlock |
CVE-2019-19721 |
|
Not Defined |
XML External Entity |
WSO2 API Manager Management Console |
CVE-2020-12719 |
Memory Corruption |
zephyrproject-rtos zephyr JSON Parser updatehub_probe |
CVE-2020-10060 |
|
Not Defined |
Code Execution |
zephyrproject-rtos zephyr Kscan Subsystem |
CVE-2020-10058 |
Memory Corruption |
zephyrproject-rtos zephyr Shell Subsystem |
CVE-2020-10023 |
|
Privilege Escalation |
zephyrproject-rtos zephyr Syscall |
CVE-2020-10028 |
|
Memory Corruption |
zephyrproject-rtos zephyr System Call Integer Overflow |
CVE-2020-10067 |
|
Privilege Escalation |
zephyrproject-rtos zephyr System Call |
CVE-2020-10024 |
|
Not Defined |
Weak Authentication |
zephyrproject-rtos zephyr UpdateHub Module Man-in-the-Middle |
CVE-2020-10059 |
Memory Corruption |
zephyrproject-rtos zephyr UpdateHub Server |
CVE-2020-10022 |
|
Memory Corruption |
zephyrproject-rtos zephyr USB DFU |
CVE-2020-10019 |
|
Memory Corruption |
zephyrproject-rtos zephyr USB Mass Storage memoryWrite |
CVE-2020-10021 |
|
Code Execution |
zephyrproject-rtos zephyr User Thread |
CVE-2020-10027 |
|
Directory Traversal |
Zoho ManageEngine DataSecurity Plus DataEngine Xnode Server Application |
CVE-2020-11531 |
|
Weak Authentication |
Zoho ManageEngine DataSecurity Plus DataEngine Xnode Server Default Credentials |
CVE-2020-11532 |
|
XSS |
Zoho ManageEngine ServiceDesk Plus Asset |
CVE-2019-15083 |
|
Weak Authentication |
Zulip Desktop SSL Certificate Validator |
CVE-2020-12637 |
خوشبختانه برای ۶۸% آسیبپذیریهای هفته، بهروزرسانیها و یا وصلههایی رسماً ارائه شده که برای جلوگیری از سوءاستفاده از آسیبپذیریها بهتر است سریعاً اعمال شوند.
همچنین با ۱۱۹ مورد، اکثر آسیبپذیریهای هفته (۳۰%) از نوع «تخریب حافظه» بودند.