|
197811
|
9.8 |
CRITICAL
Network
|
librewireless
|
ls9_firmware
|
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is Unauthenticated Root ADB Access Over TCP. The LS9 web interface provides functionality to access ADB over TCP. This is not …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-35757
|
2024-11-21 14:28 |
2021-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197812
|
7.5 |
HIGH
Network
|
librewireless
|
ls9_firmware
|
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service GETPASS Configuration Password Information Leak. The luci_service daemon running on port 7777 does not requi…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-35756
|
2024-11-21 14:28 |
2021-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197813
|
7.5 |
HIGH
Network
|
librewireless
|
ls9_firmware
|
An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service Read_ NVRAM Direct Access Information Leak. The luci_service deamon running on port 7777 provides a sub-cate…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-35755
|
2024-11-21 14:28 |
2021-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197814
|
7.8 |
HIGH
Local
|
gpac
|
gpac
|
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function gf_hinter_track_finalize() in media_tools/isom_hinter.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-35982
|
2024-11-21 14:28 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197815
|
7.8 |
HIGH
Local
|
gpac
|
gpac
|
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function SetupWriters() in isomedia/isom_store.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-35981
|
2024-11-21 14:28 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197816
|
7.8 |
HIGH
Local
|
gpac
|
gpac
|
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a use-after-free in the function gf_isom_box_del() in isomedia/box_funcs.c.
|
CWE-416
Use After Free
|
CVE-2020-35980
|
2024-11-21 14:28 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197817
|
7.8 |
HIGH
Local
|
gpac
|
gpac
|
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is heap-based buffer overflow in the function gp_rtp_builder_do_avc() in ietf/rtp_pck_mpeg4.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35979
|
2024-11-21 14:28 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197818
|
9.8 |
CRITICAL
Network
|
qnap
|
qts media_streaming_add-on multimedia_console
|
An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain applica…
|
CWE-89
SQL Injection
|
CVE-2020-36195
|
2024-11-21 14:28 |
2021-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197819
|
4.8 |
MEDIUM
Network
|
solarwinds
|
orion_platform
|
SolarWinds Orion Platform before 2020.2.5 allows stored XSS attacks by an administrator on the Customize View page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35856
|
2024-11-21 14:28 |
2021-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197820
|
5.3 |
MEDIUM
Network
|
redash
|
redash
|
Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks…
|
CWE-74
Injection
|
CVE-2020-36144
|
2024-11-21 14:28 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|