|
198141
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).
|
CWE-863
Incorrect Authorization
|
CVE-2020-35682
|
2024-11-21 14:27 |
2021-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198142
|
6.5 |
MEDIUM
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external attackers to force device reboots by sending concurrent connections, aka a den…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-35233
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198143
|
8.8 |
HIGH
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue that allows an attacker to bypass access controls and obtain full control of th…
|
CWE-287
Improper Authentication
|
CVE-2020-35231
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198144
|
6.8 |
MEDIUM
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
Multiple integer overflow parameters were found in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices. Most of the integer parameters sent through the web server can be abuse…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-35230
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198145
|
8.8 |
HIGH
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can be reused until a new token is generated, which all…
|
CWE-384
Session Fixation
|
CVE-2020-35229
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198146
|
4.8 |
MEDIUM
Network
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
A cross-site scripting (XSS) vulnerability in the administration web panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote attackers to inject arbitrary web script or HTML via the langua…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35228
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198147
|
7.2 |
HIGH
Network
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the administration web panel) allows an attacker to inject IP addresses into the white…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-35227
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198148
|
7.1 |
HIGH
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sending the corresponding write request command.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-35226
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198149
|
6.8 |
MEDIUM
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was not properly validating the length of string parameters sent in write requests, potentially allowing denial of serv…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-35225
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198150
|
6.5 |
MEDIUM
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
A buffer overflow vulnerability in the NSDP protocol authentication method on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote unauthenticated attackers to force a device reboot.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-35224
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|