|
209131
|
8.0 |
HIGH
Adjacent
|
realtek
|
rtl8710c_firmware rtl8195a_firmware
|
A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "AES_UnWRAP" function, when an attacker in Wi-Fi range sends a crafted "Encrypted …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-27301
|
2024-11-21 14:21 |
2021-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209132
|
6.5 |
MEDIUM
Local
|
qemu
|
qemu
|
A divide-by-zero issue was found in dwc2_handle_packet in hw/usb/hcd-dwc2.c in the hcd-dwc2 USB host controller emulation of QEMU. A malicious guest could use this flaw to crash the QEMU process on t…
|
CWE-369
Divide By Zero
|
CVE-2020-27661
|
2024-11-21 14:21 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209133
|
4.8 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
A cross-site scripting (XSS) vulnerability was discovered in the Administrator panel on the 'Setting News' module on CMS Made Simple 2.2.14 which allows an attacker to execute arbitrary web scripts.
|
CWE-79
Cross-site Scripting
|
CVE-2020-27377
|
2024-11-21 14:21 |
2021-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209134
|
6.5 |
MEDIUM
Network
|
freedesktop
|
xdg-utils
|
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderb…
|
-
|
CVE-2020-27748
|
2024-11-21 14:21 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209135
|
9.8 |
CRITICAL
Network
|
linuxfoundation
|
dex
|
A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest th…
|
-
|
CVE-2020-27847
|
2024-11-21 14:21 |
2021-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209136
|
4.2 |
MEDIUM
Network
|
redhat
|
keycloak single_sign-on
|
A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribut…
|
-
|
CVE-2020-27826
|
2024-11-21 14:21 |
2021-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209137
|
9.0 |
CRITICAL
Network
|
redhat
|
quay
|
A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. This flaw allows an attacker to trick a user into per…
|
-
|
CVE-2020-27832
|
2024-11-21 14:21 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209138
|
4.3 |
MEDIUM
Network
|
redhat
|
quay
|
A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add e…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-27831
|
2024-11-21 14:21 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209139
|
5.4 |
MEDIUM
Network
|
redhat
|
ceph
|
A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser’s localStorage which is potentially vulnerable to attack…
|
-
|
CVE-2020-27839
|
2024-11-21 14:21 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209140
|
7.8 |
HIGH
Local
|
linux debian netapp
|
linux_kernel debian_linux h300s_firmware h500s_firmware h700s_firmware h300e_firmware h500e_firmware h700e_firmware h410s_firmware h410c_firmware aff_a250_firmware fa…
|
A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating …
|
-
|
CVE-2020-27815
|
2024-11-21 14:21 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|