|
210471
|
7.5 |
HIGH
Network
|
mv
|
mconnect
|
Information disclosure in Logon Page in MV's mConnect application v02.001.00 allows an attacker to know valid users from the application's database via brute force.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-23283
|
2024-11-21 14:13 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210472
|
7.5 |
HIGH
Network
|
mv
|
mconnect
|
SQL injection in Logon Page in MV's mConnect application, v02.001.00, allows an attacker to use a non existing user with a generic password to connect to the application and get access to unauthorize…
|
CWE-89
SQL Injection
|
CVE-2020-23282
|
2024-11-21 14:13 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210473
|
7.5 |
HIGH
Network
|
mv
|
idce
|
Information disclosure in aspx pages in MV's IDCE application v1.0 allows an attacker to copy and paste aspx pages in the end of the URL application that connect into the database which reveals inter…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-23284
|
2024-11-21 14:13 |
2021-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210474
|
7.5 |
HIGH
Network
|
baidu
|
xuperchain
|
An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partial signature in multisignature.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-22741
|
2024-11-21 14:13 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210475
|
7.5 |
HIGH
Network
|
att
|
alienvault_ossim
|
A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system crash triggered by the occurrence of a large number of alarm events.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-22650
|
2024-11-21 14:13 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210476
|
7.5 |
HIGH
Network
|
jsish
|
jsish
|
Stack overflow vulnerability in function jsi_evalcode_sub in jsish before 3.0.18, allows remote attackers to cause a Denial of Service via a crafted value to the execute parameter.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-22907
|
2024-11-21 14:13 |
2021-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210477
|
7.5 |
HIGH
Network
|
artifex
|
mujs
|
Buffer overflow vulnerability in function jsG_markobject in jsgc.c in mujs before 1.0.8, allows remote attackers to cause a denial of service.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-22886
|
2024-11-21 14:13 |
2021-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210478
|
7.5 |
HIGH
Network
|
artifex
|
mujs
|
Buffer overflow vulnerability in mujs before 1.0.8 due to recursion in the GC scanning phase, allows remote attackers to cause a denial of service.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-22885
|
2024-11-21 14:13 |
2021-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210479
|
9.8 |
CRITICAL
Network
|
espruino
|
espruino
|
Buffer overflow vulnerability in function jsvGetStringChars in Espruino before RELEASE_2V09, allows remote attackers to execute arbitrary code.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-22884
|
2024-11-21 14:13 |
2021-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210480
|
7.5 |
HIGH
Network
|
moddable
|
moddable
|
Issue was discovered in the fxParserTree function in moddable, allows attackers to cause denial of service via a crafted payload. Fixed in commit 723816ab9b52f807180c99fc69c7d08cf6c6bd61.
|
CWE-843
Type Confusion
|
CVE-2020-22882
|
2024-11-21 14:13 |
2021-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|