CVE-2020-4760
published 2020-11-10CVE-2020-4760: IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus…
PriorityP424medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.85%
53.9th percentile
IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188737.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | content_navigator | — | — |
| ibm | content_navigator | — | — |
| linux | linux_kernel | >= 6.4.0 < 6.4.4 | 6.4.4 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
vduse: fix NULL pointer dereference
osv·2025-12-30
CVE-2023-54291 vduse: fix NULL pointer dereference
vduse: fix NULL pointer dereference
In the Linux kernel, the following vulnerability has been resolved:
vduse: fix NULL pointer dereference
vduse_vdpa_set_vq_affinity callback can be called
with NULL value as cpu_mask when deleting the vduse
device.
This patch resets virtqueue's IRQ affinity mask value
to set all CPUs instead of dereferencing NULL cpu_mask.
[ 4760.952149] BUG: kernel NULL pointer dereference, address: 0000000000000000
[ 4760.959110] #PF: supervisor read access in kernel mode
[ 4760.964247] #PF: error_code(0x0000) - not-present page
[ 4760.969385] PGD 0 P4D 0
[ 4760.971927] Oops: 0000 [#1] PREEMPT SMP PTI
[ 4760.976112] CPU: 13 PID: 2346 Comm: vdpa Not tainted 6.4.0-rc6+ #4
[ 4760.982291] Hardware name: Dell Inc. PowerEdge R640/0W23H8, BIOS 2.8.1 06/26/2020
[ 4760.9897
GHSA
GHSA-m785-q8fj-8w82: IBM Content Navigator 3
ghsa_unreviewed·2022-05-24
CVE-2020-4760 [MEDIUM] CWE-79 GHSA-m785-q8fj-8w82: IBM Content Navigator 3
IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188737.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-14468 tcpdump: Buffer over-read in mfr_print() function in print-fr.c
bugzilla·2019-10-10·CVSS 7.5
CVE-2018-14468 [HIGH] CVE-2018-14468 tcpdump: Buffer over-read in mfr_print() function in print-fr.c
CVE-2018-14468 tcpdump: Buffer over-read in mfr_print() function in print-fr.c
The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().
Upstream patch:
https://github.com/the-tcpdump-group/tcpdump/commit/aa3e54f594385ce7e1e319b0c84999e51192578b
References:
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1760626]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-14468
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4760 https://access.redhat.com/errata/RHSA-2020:4760
Bugzilla
CVE-2018-14470 tcpdump: Buffer over-read in babel_print_v2() in print-babel.c
bugzilla·2019-10-10·CVSS 7.5
CVE-2018-14470 [HIGH] CVE-2018-14470 tcpdump: Buffer over-read in babel_print_v2() in print-babel.c
CVE-2018-14470 tcpdump: Buffer over-read in babel_print_v2() in print-babel.c
The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2().
Upstream patch:
https://github.com/the-tcpdump-group/tcpdump/commit/12f66f69f7bf1ec1266ddbee90a7616cbf33696b
References:
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1760626]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-14470
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4760 https://access.redhat.com/errata/RHSA-2020:4760
Bugzilla
CVE-2018-16300 tcpdump: Resource exhaustion in bgp_attr_print() function in print-bgp.c
bugzilla·2019-10-10·CVSS 7.5
CVE-2018-16300 [HIGH] CVE-2018-16300 tcpdump: Resource exhaustion in bgp_attr_print() function in print-bgp.c
CVE-2018-16300 tcpdump: Resource exhaustion in bgp_attr_print() function in print-bgp.c
The BGP parser in tcpdump before 4.9.3 allows stack consumption in print-bgp.c:bgp_attr_print() because of unlimited recursion.
Upstream patch:
https://github.com/the-tcpdump-group/tcpdump/commit/af2cf04a9394c1a56227c2289ae8da262828294a
References:
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1760626]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-16300
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4760 https://access.redh
Bugzilla
CVE-2018-16227 tcpdump: Buffer over-read in print-802_11.c
bugzilla·2019-10-10·CVSS 7.5
CVE-2018-16227 [HIGH] CVE-2018-16227 tcpdump: Buffer over-read in print-802_11.c
CVE-2018-16227 tcpdump: Buffer over-read in print-802_11.c
The IEEE 802.11 parser in tcpdump before 4.9.3 has a buffer over-read in print-802_11.c for the Mesh Flags subfield.
Upstream patch:
https://github.com/the-tcpdump-group/tcpdump/commit/4846b3c5d0a850e860baf4f07340495d29837d09
References:
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1760626]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-16227
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4760 https://access.redhat.com/errata/RHSA-2020:4760
Bugzilla
CVE-2018-16230 tcpdump: Buffer over-read in bgp_attr_print() function in print-bgp.c
bugzilla·2019-10-10·CVSS 7.5
CVE-2018-16230 [HIGH] CVE-2018-16230 tcpdump: Buffer over-read in bgp_attr_print() function in print-bgp.c
CVE-2018-16230 tcpdump: Buffer over-read in bgp_attr_print() function in print-bgp.c
The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_REACH_NLRI).
Upstream patch:
https://github.com/the-tcpdump-group/tcpdump/commit/13d52e9c0e7caf7e6325b0051bc90a49968be67f
References:
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1760626]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-16230
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4760 https://access.redhat.com/errata/RHSA-2
Bugzilla
CVE-2019-15166 tcpdump: Buffer overflow in lmp_print_data_link_subobjs() in print-lmp.c
bugzilla·2019-10-10·CVSS 1.6
CVE-2019-15166 [LOW] CVE-2019-15166 tcpdump: Buffer overflow in lmp_print_data_link_subobjs() in print-lmp.c
CVE-2019-15166 tcpdump: Buffer overflow in lmp_print_data_link_subobjs() in print-lmp.c
lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.
Upstream patch:
https://github.com/the-tcpdump-group/tcpdump/commit/0b661e0aa61850234b64394585cf577aac570bf4
References:
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1760626]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-15166
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4760 https://access.redhat.com/errata/RHSA-2020:4760
Bugzilla
CVE-2018-14462 tcpdump: Buffer over-read in icmp_print() function in print-icmp.c
bugzilla·2019-10-10·CVSS 7.5
CVE-2018-14462 [HIGH] CVE-2018-14462 tcpdump: Buffer over-read in icmp_print() function in print-icmp.c
CVE-2018-14462 tcpdump: Buffer over-read in icmp_print() function in print-icmp.c
The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().
Upstream patch:
https://github.com/the-tcpdump-group/tcpdump/commit/1a1bce0526a77b62e41531b00f8bb5e21fd4f3a3
References:
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1760626]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-14462
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4760 https://access.redhat.com/errata/RHSA-2020:4760
Bugzilla
CVE-2018-14880 tcpdump: Buffer over-read in ospf6_print_lshdr() function in print-ospf6.c
bugzilla·2019-10-10·CVSS 7.5
CVE-2018-14880 [HIGH] CVE-2018-14880 tcpdump: Buffer over-read in ospf6_print_lshdr() function in print-ospf6.c
CVE-2018-14880 tcpdump: Buffer over-read in ospf6_print_lshdr() function in print-ospf6.c
The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr().
Upstream patch:
https://github.com/the-tcpdump-group/tcpdump/commit/e01c9bf76740802025c9328901b55ee4a0c49ed6
References:
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1760626]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-14880
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4760 https://access.redhat.com/errata/RHSA-2020
Bugzilla
CVE-2018-14881 tcpdump: Buffer over-read in bgp_capabilities_print() function in print-bgp.c
bugzilla·2019-10-10·CVSS 7.5
CVE-2018-14881 [HIGH] CVE-2018-14881 tcpdump: Buffer over-read in bgp_capabilities_print() function in print-bgp.c
CVE-2018-14881 tcpdump: Buffer over-read in bgp_capabilities_print() function in print-bgp.c
The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTART).
Upstream patch:
https://github.com/the-tcpdump-group/tcpdump/commit/86326e880d31b328a151d45348c35220baa9a1ff
References:
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1760626]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-14881
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4760 https://access.re
Bugzilla
CVE-2018-14467 tcpdump: Buffer over-read in bgp_capabilities_print() in print-bgp.c
bugzilla·2019-10-10·CVSS 7.5
CVE-2018-14467 [HIGH] CVE-2018-14467 tcpdump: Buffer over-read in bgp_capabilities_print() in print-bgp.c
CVE-2018-14467 tcpdump: Buffer over-read in bgp_capabilities_print() in print-bgp.c
The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_MP).
Upstream patch:
https://github.com/the-tcpdump-group/tcpdump/commit/e3f3b445e2d20ac5d5b7fcb7559ce6beb55da0c9
References:
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1760626]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-14467
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4760 https://access.redhat.com/errat
Bugzilla
CVE-2018-16451 tcpdump: Buffer over-read in print_trans() function in print-smb.c
bugzilla·2019-10-10·CVSS 7.5
CVE-2018-16451 [HIGH] CVE-2018-16451 tcpdump: Buffer over-read in print_trans() function in print-smb.c
CVE-2018-16451 tcpdump: Buffer over-read in print_trans() function in print-smb.c
The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN.
Upstream patch:
https://github.com/the-tcpdump-group/tcpdump/commit/96480ab95308cd9234b4f09b175ebf60e17792c6
References:
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1760626]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-16451
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4760 https://access.redhat.co
Bugzilla
CVE-2018-16452 tcpdump: Resource exhaustion in smb_fdata() funtion in smbutil.c
bugzilla·2019-10-10·CVSS 7.5
CVE-2018-16452 [HIGH] CVE-2018-16452 tcpdump: Resource exhaustion in smb_fdata() funtion in smbutil.c
CVE-2018-16452 tcpdump: Resource exhaustion in smb_fdata() funtion in smbutil.c
The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smb_fdata() via recursion.
Upstream patch:
https://github.com/the-tcpdump-group/tcpdump/commit/24182d959f661327525a20d9a94c98a8ec016778
References:
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1760626]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-16452
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4760 https://access.redhat.com/errata/RHSA-2020:4760
Bugzilla
CVE-2018-14464 tcpdump: Buffer over-read in lmp_print_data_link_subobjs() function in print-lmp.c
bugzilla·2019-10-10·CVSS 7.5
CVE-2018-14464 [HIGH] CVE-2018-14464 tcpdump: Buffer over-read in lmp_print_data_link_subobjs() function in print-lmp.c
CVE-2018-14464 tcpdump: Buffer over-read in lmp_print_data_link_subobjs() function in print-lmp.c
The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs().
Upstream patch:
https://github.com/the-tcpdump-group/tcpdump/commit/d97e94223720684c6aa740ff219e0d19426c2220
References:
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1760626]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-14464
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4760 https://access.redhat.com/err
Bugzilla
CVE-2018-14461 tcpdump: Buffer over-read in ldp_tlv_print() function in print-ldp.c
bugzilla·2019-10-10·CVSS 7.5
CVE-2018-14461 [HIGH] CVE-2018-14461 tcpdump: Buffer over-read in ldp_tlv_print() function in print-ldp.c
CVE-2018-14461 tcpdump: Buffer over-read in ldp_tlv_print() function in print-ldp.c
The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().
Upstream patch:
https://github.com/the-tcpdump-group/tcpdump/commit/aa5c6b710dfd8020d2c908d6b3bd41f1da719b3b
References:
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1760626]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-14461
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4760 https://access.redhat.com/errata/RHSA-2020:4760
Bugzilla
CVE-2018-14463 tcpdump: Buffer over-read in vrrp_print() function in print-vrrp.c
bugzilla·2019-10-10·CVSS 7.5
CVE-2018-14463 [HIGH] CVE-2018-14463 tcpdump: Buffer over-read in vrrp_print() function in print-vrrp.c
CVE-2018-14463 tcpdump: Buffer over-read in vrrp_print() function in print-vrrp.c
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print().
Upstream patch:
https://github.com/the-tcpdump-group/tcpdump/commit/3de07c772166b7e8e8bb4b9d1d078f1d901b570b
References:
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1760626]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-14463
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4760 https://access.redhat.com/errata/RHSA-2020:4760
Bugzilla
CVE-2018-16229 tcpdump: Buffer over-read in dccp_print_option() function in print-dccp.c
bugzilla·2019-10-10·CVSS 7.5
CVE-2018-16229 [HIGH] CVE-2018-16229 tcpdump: Buffer over-read in dccp_print_option() function in print-dccp.c
CVE-2018-16229 tcpdump: Buffer over-read in dccp_print_option() function in print-dccp.c
The DCCP parser in tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option().
Upstream patch:
https://github.com/the-tcpdump-group/tcpdump/commit/211124b972e74f0da66bc8b16f181f78793e2f66
References:
https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1760626]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-16229
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4760 https://access.redhat.com/errata/RHSA-2020:476
2020-11-10
Published