|
199881
|
6.5 |
MEDIUM
Network
|
tag_project
|
tag
|
dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readAtomData.
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-29245
|
2024-11-21 14:23 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199882
|
6.5 |
MEDIUM
Network
|
tag_project
|
tag
|
dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readTextWithDescrFrame.
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-29244
|
2024-11-21 14:23 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199883
|
6.5 |
MEDIUM
Network
|
tag_project
|
tag
|
dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readAPICFrame.
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-29243
|
2024-11-21 14:23 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199884
|
6.5 |
MEDIUM
Network
|
tag_project
|
tag
|
dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readPICFrame.
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-29242
|
2024-11-21 14:23 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199885
|
7.5 |
HIGH
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.
|
CWE-862
Missing Authorization
|
CVE-2020-29160
|
2024-11-21 14:23 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199886
|
4.9 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.5.1. The default signup Role (for newly created Users) can be a privileged Role, if configured by an admin. This behvaior was unintended.
|
NVD-CWE-noinfo
|
CVE-2020-29159
|
2024-11-21 14:23 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199887
|
4.3 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 3.5.1. An Agent with Customer permissions in a Group can bypass intended access control on internal Articles via the Ticket detail view.
|
CWE-862
Missing Authorization
|
CVE-2020-29158
|
2024-11-21 14:23 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199888
|
7.5 |
HIGH
Network
|
panasonic
|
wv-s2231l_firmware
|
Panasonic Security System WV-S2231L 4.25 allows a denial of service of the admin control panel (which will require a physical reset to restore administrative control) via Randomnum=99AC8CEC6E845B28&m…
|
NVD-CWE-noinfo
|
CVE-2020-29194
|
2024-11-21 14:23 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199889
|
6.8 |
MEDIUM
Physics
|
panasonic
|
wv-s2231l_firmware
|
Panasonic Security System WV-S2231L 4.25 has an insecure hard-coded password of lkjhgfdsa (which is just the asdf keyboard row in reverse order).
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-29193
|
2024-11-21 14:23 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199890
|
5.3 |
MEDIUM
Network
|
woocommerce
|
woocommerce
|
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-29156
|
2024-11-21 14:23 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|