|
200651
|
7.5 |
HIGH
Network
|
wireshark debian fedoraproject opensuse
|
wireshark debian_linux fedora leap
|
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c by using more careful sscanf parsing.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-9428
|
2024-11-21 14:40 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200652
|
7.5 |
HIGH
Network
|
pureftpd debian fedoraproject canonical
|
pure-ftpd debian_linux fedora extra_packages_for_enterprise_linux ubuntu_linux
|
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) fu…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2020-9274
|
2024-11-21 14:40 |
2020-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200653
|
6.5 |
MEDIUM
Network
|
golfbuddyglobal
|
course_manager
|
In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request.
|
CWE-200 CWE-326
Information Exposure Inadequate Encryption Strength
|
CVE-2020-9337
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200654
|
5.3 |
MEDIUM
Network
|
iblsoft
|
online_weather
|
IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COOKIE cookie.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-9407
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200655
|
9.8 |
CRITICAL
Network
|
iblsoft
|
online_weather
|
IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
|
CWE-94
Code Injection
|
CVE-2020-9406
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200656
|
6.1 |
MEDIUM
Network
|
iblsoft
|
online_weather
|
IBL Online Weather before 4.3.5a allows unauthenticated reflected XSS via the redirect page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9405
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200657
|
9.8 |
CRITICAL
Network
|
ispconfig
|
ispconfig
|
ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2020-9398
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200658
|
8.8 |
HIGH
Network
|
supsystic
|
pricing_table_by_supsystic
|
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-9394
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200659
|
6.1 |
MEDIUM
Network
|
supsystic
|
pricing_table_by_supsystic
|
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9393
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200660
|
6.5 |
MEDIUM
Network
|
mitel
|
micontact_center_business
|
The Software Development Kit of the MiContact Center Business with Site Based Security 8.0 through 9.0.1.0 before KB496276 allows an authenticated user to access sensitive information. A successful e…
|
NVD-CWE-noinfo
|
CVE-2020-9379
|
2024-11-21 14:40 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|