|
209441
|
7.8 |
HIGH
Local
|
cybereason
|
endpoint_detection_and_response
|
Cybereason EDR version 19.1.282 and above, 19.2.182 and above, 20.1.343 and above, and 20.2.X and above has a DLL hijacking vulnerability, which could allow a local attacker to execute code with elev…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-25502
|
2024-11-21 14:18 |
2023-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209442
|
6.1 |
MEDIUM
Network
|
6kare
|
emakin
|
6Kare Emakin 5.0.341.0 is affected by Cross Site Scripting (XSS) via the /rpc/membership/setProfile DisplayName field, which is mishandled when rendering the Activity Stream page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25491
|
2024-11-21 14:18 |
2022-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209443
|
7.5 |
HIGH
Network
|
unix4lyfe
|
darkhttpd
|
A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-25691
|
2024-11-21 14:18 |
2022-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209444
|
8.8 |
HIGH
Network
|
samba
|
samba
|
Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a reliable SID (and samAccountName) in issued ticket…
|
CWE-20
Improper Input Validation
|
CVE-2020-25721
|
2024-11-21 14:18 |
2022-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209445
|
8.8 |
HIGH
Network
|
samba debian fedoraproject canonical
|
samba debian_linux fedora ubuntu_linux
|
Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause total domain compromise.
|
CWE-863
Incorrect Authorization
|
CVE-2020-25722
|
2024-11-21 14:18 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209446
|
8.8 |
HIGH
Network
|
samba fedoraproject
|
samba fedora
|
A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domain controller). This would allow an RODC to print administrator tickets.
|
CWE-862
Missing Authorization
|
CVE-2020-25718
|
2024-11-21 14:18 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209447
|
7.2 |
HIGH
Network
|
samba debian fedoraproject canonical redhat
|
samba debian_linux fedora ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_for_scientific_computing enterprise_linux enterprise_linux_for_po…
|
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents …
|
CWE-362
Race Condition
|
CVE-2020-25719
|
2024-11-21 14:18 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209448
|
8.1 |
HIGH
Network
|
samba debian fedoraproject redhat canonical
|
samba debian_linux fedora enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_for_scientific_computing enterprise_linux enterprise_linux_server enterprise_l…
|
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
|
CWE-20
Improper Input Validation
|
CVE-2020-25717
|
2024-11-21 14:18 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209449
|
9.8 |
CRITICAL
Network
|
mobile_shop_system_project
|
mobile_shop_system
|
An SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1) login.php or (2) LoginAsAdmin.php.
|
CWE-89
SQL Injection
|
CVE-2020-25905
|
2024-11-21 14:18 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209450
|
9.1 |
CRITICAL
Network
|
getsymphony
|
symphony
|
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).
|
CWE-611
XXE
|
CVE-2020-25912
|
2024-11-21 14:18 |
2021-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|