CVE-2020-0516
published 2020-03-12CVE-2020-0516: Improper access control in Intel(R) Graphics Drivers before version 26.20.100.7463 may allow an authenticated user to potentially enable denial of service via…
PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.56%
42.7th percentile
Improper access control in Intel(R) Graphics Drivers before version 26.20.100.7463 may allow an authenticated user to potentially enable denial of service via local access.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | graphics_driver | < 26.20.100.7463 | 26.20.100.7463 |
| intel | intel_graphics_drivers | — | — |
| intel | intel_graphics_drivers | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Nuclei
Oracle iPlanet Web Server 7.0.x - Image Injection
nuclei·CVSS 6.8
CVE-2020-9314 [MEDIUM] Oracle iPlanet Web Server 7.0.x - Image Injection
Oracle iPlanet Web Server 7.0.x - Image Injection
Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516.
Template:
id: CVE-2020-9314
info:
name: Oracle iPlanet Web Server 7.0.x - Image Injection
author: DhiyaneshDk
severity: medium
description: |
Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516.
impact: |
Attackers can inject malicious images into the admin console, potentially leading to social engineering, phishing attacks, or interface manipulation.
remediation: |
Oracle iPlanet Web Se
No writeups or analysis indexed.
http://packetstormsecurity.com/files/156761/ShaderCache-Arbitrary-File-Creation-Privilege-Escalation.htmlhttps://security.netapp.com/advisory/ntap-20200320-0003/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00315.htmlhttp://packetstormsecurity.com/files/156761/ShaderCache-Arbitrary-File-Creation-Privilege-Escalation.htmlhttps://security.netapp.com/advisory/ntap-20200320-0003/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00315.html
2020-03-12
Published