|
210351
|
6.5 |
MEDIUM
Local
|
intel debian netapp
|
microcode debian_linux solidfire_bios hci_compute_node_bios fas\/aff_bios
|
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-24511
|
2024-11-21 14:14 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210352
|
6.7 |
MEDIUM
Local
|
intel
|
server_platform_services
|
Insufficient control flow management in subsystem in Intel(R) SPS versions before SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.04.023.0, or SPS_E5_04.04.03.263.0 may allow a privileg…
|
NVD-CWE-Other
|
CVE-2020-24509
|
2024-11-21 14:14 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210353
|
4.4 |
MEDIUM
Local
|
intel siemens
|
converged_security_and_manageability_engine simatic_field_pg_m6_firmware simatic_ipc427e_firmware simatic_ipc477e_firmware simatic_ipc477e_pro_firmware simatic_ipc527g_firmware sima…
|
Improper initialization in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32, 13.50.11 and 15.0.22 may allow a privileged user…
|
CWE-665
Improper Initialization
|
CVE-2020-24507
|
2024-11-21 14:14 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210354
|
4.4 |
MEDIUM
Local
|
intel siemens
|
converged_security_and_manageability_engine simatic_field_pg_m6_firmware simatic_ipc627e_firmware simatic_ipc647e_firmware simatic_ipc677e_firmware simatic_ipc847e_firmware
|
Out of bound read in a subsystem in the Intel(R) CSME versions before 12.0.81, 13.0.47, 13.30.17, 14.1.53 and 14.5.32 may allow a privileged user to potentially enable information disclosure via loca…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-24506
|
2024-11-21 14:14 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210355
|
5.5 |
MEDIUM
Local
|
intel netapp siemens
|
bios cloud_backup hci_storage_node_bios solidfire_bios hci_compute_node_bios aff_bios fas_bios e-series_bios simatic_ipc547g_firmware
|
Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
|
CWE-20
Improper Input Validation
|
CVE-2020-24486
|
2024-11-21 14:14 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210356
|
8.8 |
HIGH
Network
|
ffmpeg
|
ffmpeg
|
Buffer Overflow vulnerability in FFMpeg 4.2.3 in dnn_execute_layer_pad in libavfilter/dnn/dnn_backend_native_layer_pad.c due to a call to memcpy without length checks, which could let a remote malici…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-24020
|
2024-11-21 14:14 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210357
|
7.5 |
HIGH
Network
|
phpyun
|
phpyun
|
An information disclosure vulnerability was discovered in alipay_function.php in the log file of Alibaba payment interface on PHPPYUN prior to version 5.0.1. If exploited, this vulnerability will all…
|
NVD-CWE-noinfo
|
CVE-2020-23768
|
2024-11-21 14:14 |
2021-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210358
|
6.5 |
MEDIUM
Network
|
htmly
|
htmly
|
An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolute path to delete any file in the server should they gain Administrator privileg…
|
CWE-22
Path Traversal
|
CVE-2020-23766
|
2024-11-21 14:14 |
2021-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210359
|
7.2 |
HIGH
Network
|
bludit
|
bludit
|
A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Administrator rights they will be able to use unsafe…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-23765
|
2024-11-21 14:14 |
2021-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210360
|
7.5 |
HIGH
Network
|
hom.ee
|
brain_cube_core
|
homee Brain Cube v2 (2.28.2 and 2.28.4) devices have sensitive SSH keys within downloadable and unencrypted firmware images. This allows remote attackers to use the support server as a SOCKS proxy.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-24396
|
2024-11-21 14:14 |
2021-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|