Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In June 2020
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.
CVSS Score
7.5
EPSS Score
0.0
Published
2020-06-17
IBM Business Automation Workflow and IBM Business Process Manager (IBM Business Process Manager Express 8.5.5, 8.5.6, 8.5.7, and 8.6) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 182716.
CVSS Score
5.3
EPSS Score
0.002
Published
2020-06-17
All versions up to 10.06 of ZTEMarket APK are impacted by an information leak vulnerability. Due to Activity Component exposure users can exploit this vulnerability to get the private cookie and execute silent installation.
CVSS Score
8.1
EPSS Score
0.003
Published
2020-06-17
OMERO before 5.6.1 makes the details of each user available to all users.
CVSS Score
5.3
EPSS Score
0.002
Published
2020-06-17
In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled.
CVSS Score
7.5
EPSS Score
0.001
Published
2020-06-17
In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image filesets may circumvent OMERO permissions restrictions. This occurs because the Bio-Formats feature allows an image file to have embedded pathnames.
CVSS Score
7.5
EPSS Score
0.002
Published
2020-06-17
An issue was discovered in the stashcat app through 3.9.2 for macOS, Windows, Android, iOS, and possibly other platforms. It stores the client_key, the device_id, and the public key for end-to-end encryption in cleartext, enabling an attacker (by copying or having access to the local storage database file) to login to the system from any other computer, and get unlimited access to all data in the users's context.
CVSS Score
7.5
EPSS Score
0.001
Published
2020-06-17
In OMERO before 5.6.1, group owners can access members' data in other groups.
CVSS Score
3.8
EPSS Score
0.002
Published
2020-06-17
OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, the information in the query parameters may be exposed in the Referer header seen by the target. Information in the URL path such as object IDs may also be exposed.
CVSS Score
5.7
EPSS Score
0.003
Published
2020-06-17
ftusbbus2.sys in FabulaTech USB for Remote Desktop through 2020-02-19 allows privilege escalation via crafted IoCtl code related to a USB HID device.
CVSS Score
7.8
EPSS Score
0.001
Published
2020-06-17


Contact Us

Shodan ® - All rights reserved