|
211421
|
7.8 |
HIGH
Local
|
deltaww
|
ispsoft
|
A use after free issue has been identified in the way ISPSoft(v3.12 and prior) processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution.
|
CWE-416
Use After Free
|
CVE-2020-27280
|
2024-11-21 14:20 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211422
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible way to access contacts due to a permissions bypass. This could lead to local information disclosure with no additional …
|
NVD-CWE-noinfo
|
CVE-2020-27098
|
2024-11-21 14:20 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211423
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. Use…
|
NVD-CWE-noinfo
|
CVE-2020-27097
|
2024-11-21 14:20 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211424
|
5.5 |
MEDIUM
Local
|
eset
|
security mail_security file_security endpoint_security endpoint_antivirus smart_security internet_security nod32_antivirus
|
A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwrite (deletion) of any file via a symlink, due to insecure permissions. The poss…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-26941
|
2024-11-21 14:20 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211425
|
9.8 |
CRITICAL
Network
|
eclipse
|
openj9
|
In Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encod…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-27221
|
2024-11-21 14:20 |
2021-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211426
|
5.7 |
MEDIUM
Adjacent
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications lacks replay protection measur…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2020-27269
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211427
|
6.5 |
MEDIUM
Adjacent
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically pro…
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2020-27268
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211428
|
6.5 |
MEDIUM
Adjacent
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically pro…
|
CWE-287
Improper Authentication
|
CVE-2020-27266
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211429
|
8.8 |
HIGH
Adjacent
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications use deterministic keys, which …
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-27264
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211430
|
6.5 |
MEDIUM
Adjacent
|
sooil
|
anydana-i anydana-a dana_diabecare_rs_firmware
|
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-27258
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|