|
196761
|
7.5 |
HIGH
Network
|
huawei
|
cloudengine_12800_firmware cloudengine_5800_firmware cloudengine_6800_firmware cloudengine_7800_firmware
|
There is an out of bound read vulnerability in some verisons of Huawei CloudEngine product. A module does not deal with specific message properly. Attackers can exploit this vulnerability by sending …
|
CWE-125
Out-of-bounds Read
|
CVE-2020-9094
|
2024-11-21 14:40 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196762
|
5.5 |
MEDIUM
Local
|
huawei
|
taurus-al00a_firmware
|
There is a use after free vulnerability in Taurus-AL00A versions 10.0.0.1(C00E1R1P1). A module does not deal with specific message properly, which makes a function refer to memory after it has been f…
|
CWE-416
Use After Free
|
CVE-2020-9093
|
2024-11-21 14:40 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196763
|
4.4 |
MEDIUM
Local
|
huawei
|
te_mobile
|
There is an information disclosure vulnerability in TE Mobile software versions V600R006C10,V600R006C10SPC100. Due to the improper storage of some information in certain specific scenario, the attack…
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2020-9202
|
2024-11-21 14:40 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196764
|
6.5 |
MEDIUM
Adjacent
|
huawei
|
nip6800_firmware secospace_usg6600_firmware usg9500_firmware
|
There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9500. The software reads data past the end of the intended buffer when parsing DHCP messages includi…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-9201
|
2024-11-21 14:40 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196765
|
7.8 |
HIGH
Local
|
huawei
|
imanager_neteco_6000
|
There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files.…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-9200
|
2024-11-21 14:40 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196766
|
6.7 |
MEDIUM
Local
|
huawei
|
cloudengine_12800_firmware cloudengine_5800_firmware cloudengine_6800_firmware cloudengine_7800_firmware
|
There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 and CloudEngine 7800. Due to insufficient input validation, a local attacker with…
|
CWE-20
Improper Input Validation
|
CVE-2020-9137
|
2024-11-21 14:40 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196767
|
7.5 |
HIGH
Network
|
huawei
|
cloudengine_1800v
|
CloudEngine 1800V versions V100R019C10SPC500 has a resource management error vulnerability. Remote unauthorized attackers could send specific types of messages to the device, resulting in the message…
|
NVD-CWE-Other
|
CVE-2020-9120
|
2024-11-21 14:40 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196768
|
6.2 |
MEDIUM
Physics
|
huawei
|
mate_10_firmware mate_30_firmware mate_30_pro_firmware p40_firmware p40_pro_firmware
|
There is a privilege escalation vulnerability on some Huawei smart phones due to design defects. The attacker needs to physically contact the mobile phone and obtain higher privileges, and execute re…
|
NVD-CWE-noinfo
|
CVE-2020-9119
|
2024-11-21 14:40 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196769
|
6.1 |
MEDIUM
Network
|
uncannyowl
|
tin_canny_reporting_for_learndash
|
Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Owl Tin Canny LearnDash Reporting before 3.4.4 allows authenticated remote attackers to inject arbitrary web script or HTML via the sear…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9439
|
2024-11-21 14:40 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196770
|
8.8 |
HIGH
Network
|
linuxfoundation
|
spinnaker
|
Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpE…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-9301
|
2024-11-21 14:40 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|