|
197151
|
5.5 |
MEDIUM
Local
|
qualcomm
|
apq8009_firmware apq8053_firmware apq8096au_firmware apq8098_firmware bitra_firmware kamorta_firmware mdm9206_firmware mdm9150_firmware mdm9607_firmware mdm9640_firmware
|
u'Lack of check to ensure that the TX read index & RX write index that are read from shared memory are less than the FIFO size results into memory corruption and potential information leakage' in Sna…
|
CWE-20 CWE-787
Improper Input Validation Out-of-bounds Write
|
CVE-2020-3621
|
2024-11-21 14:31 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197152
|
5.5 |
MEDIUM
Local
|
qualcomm
|
apq8009_firmware apq8053_firmware apq8096au_firmware apq8098_firmware bitra_firmware kamorta_firmware mdm9206_firmware mdm9150_firmware mdm9607_firmware mdm9640_firmware
|
u'Lack of check of integer overflow while doing a round up operation for data read from shared memory for G-link SMEM transport can lead to corruption and potential information leak' in Snapdragon Au…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-3620
|
2024-11-21 14:31 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197153
|
7.0 |
HIGH
Local
|
qualcomm
|
apq8009_firmware apq8017_firmware apq8053_firmware apq8098_firmware ipq8074_firmware kamorta_firmware mdm9150_firmware mdm9206_firmware mdm9607_firmware mdm9650_firmware
|
u'Non-secure memory is touched multiple times during TrustZone\u2019s execution and can lead to privilege escalation or memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectiv…
|
CWE-787 CWE-367
Out-of-bounds Write Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2020-3619
|
2024-11-21 14:31 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197154
|
7.8 |
HIGH
Local
|
qualcomm
|
apq8098_firmware kamorta_firmware msm8998_firmware qcs404_firmware qcs605_firmware sda660_firmware sda845_firmware sdm630_firmware sdm636_firmware sdm660_firmware sdm670…
|
u'XBL SEC clears only ZI region when loading Qualcomm-signed segments can lead to improper access issue' in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, …
|
NVD-CWE-noinfo
|
CVE-2020-3611
|
2024-11-21 14:31 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197155
|
6.5 |
MEDIUM
Network
|
cisco
|
jabber
|
A vulnerability in Cisco Jabber software could allow an authenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of message contents. An…
|
CWE-20
Improper Input Validation
|
CVE-2020-3498
|
2024-11-21 14:31 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197156
|
6.8 |
MEDIUM
Adjacent
|
cisco
|
rv340w_firmware rv340_firmware rv345_firmware rv345p_firmware
|
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 Series Routers could allow an authenticated, remote attacker with administrative credentials to execute ar…
|
CWE-20
Improper Input Validation
|
CVE-2020-3453
|
2024-11-21 14:31 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197157
|
4.7 |
MEDIUM
Network
|
cisco
|
rv340w_firmware rv340_firmware rv345_firmware rv345p_firmware
|
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 Series Routers could allow an authenticated, remote attacker with administrative credentials to execute ar…
|
CWE-20
Improper Input Validation
|
CVE-2020-3451
|
2024-11-21 14:31 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197158
|
6.5 |
MEDIUM
Network
|
cisco
|
asyncos
|
A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security App…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-3547
|
2024-11-21 14:31 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197159
|
5.3 |
MEDIUM
Network
|
cisco
|
asyncos
|
A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to access sensitive informatio…
|
CWE-20
Improper Input Validation
|
CVE-2020-3546
|
2024-11-21 14:31 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197160
|
6.7 |
MEDIUM
Local
|
cisco
|
firepower_extensible_operating_system
|
A vulnerability in Cisco FXOS Software could allow an authenticated, local attacker with administrative credentials to cause a buffer overflow condition. The vulnerability is due to incorrect bounds …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-3545
|
2024-11-21 14:31 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|