|
210141
|
6.7 |
MEDIUM
Local
|
dpdk canonical fedoraproject opensuse oracle
|
data_plane_development_kit ubuntu_linux fedora leap enterprise_communications_broker communications_session_border_controller
|
A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing…
|
-
|
CVE-2020-10722
|
2024-11-21 13:55 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210142
|
5.0 |
MEDIUM
Local
|
redhat
|
ansible_tower ansible
|
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the…
|
CWE-362
Race Condition
|
CVE-2020-10744
|
2024-11-21 13:55 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210143
|
9.8 |
CRITICAL
Network
|
opto22
|
softpac_project
|
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with SoftPAC, including, for…
|
CWE-862
Missing Authorization
|
CVE-2020-10620
|
2024-11-21 13:55 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210144
|
8.8 |
HIGH
Network
|
opto22
|
softpac_project
|
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC does not specify the path of multiple imported .dll files. Therefore, an attacker can replace them and execute code whenever the service starts.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-10616
|
2024-11-21 13:55 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210145
|
9.1 |
CRITICAL
Network
|
opto22
|
softpac_project
|
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPACAgent communicates with SoftPACMonitor over network Port 22000. However, this port is open without any restrictions. This allows an attacker with…
|
CWE-862
Missing Authorization
|
CVE-2020-10612
|
2024-11-21 13:55 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210146
|
7.8 |
HIGH
Local
|
fazecast schneider-electric
|
jserialcomm ecostruxure_it_gateway
|
In Fazecast jSerialComm, Version 2.2.2 and prior, an uncontrolled search path element vulnerability could allow a malicious DLL file with the same name of any resident DLLs inside the software instal…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-10626
|
2024-11-21 13:55 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210147
|
9.8 |
CRITICAL
Network
|
pingidentity
|
pingid_ssh_integration
|
Ping Identity PingID SSH before 4.0.14 contains a heap buffer overflow in PingID-enrolled servers. This condition can be potentially exploited into a Remote Code Execution vector on the authenticatin…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10654
|
2024-11-21 13:55 |
2020-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210148
|
6.6 |
MEDIUM
Physics
|
redhat
|
openshift_container_platform
|
A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allows an attacker with access to a backup to obtain OA…
|
-
|
CVE-2020-10706
|
2024-11-21 13:55 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210149
|
5.5 |
MEDIUM
Local
|
redhat debian
|
ansible_tower ansible_engine ceph_storage openstack storage debian_linux
|
A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 an…
|
CWE-459
Incomplete Cleanup
|
CVE-2020-10685
|
2024-11-21 13:55 |
2020-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210150
|
6.4 |
MEDIUM
Local
|
linux redhat debian canonical opensuse netapp
|
linux_kernel enterprise_linux debian_linux ubuntu_linux leap element_software steelstore_cloud_integrated_storage solidfire hci_management_node active_iq_unified_manager
|
There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp…
|
CWE-416
Use After Free
|
CVE-2020-10690
|
2024-11-21 13:55 |
2020-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|