|
210061
|
8.8 |
HIGH
Network
|
netgear
|
d6220_firmware d6400_firmware d8500_firmware r6220_firmware r6250_firmware r6260_firmware r6400_firmware r6700_firmware r6800_firmware r6900_firmware r6900p_firmware …
|
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000v2 before 1.0.0.53, D8500 before 1.0.3.44, R6220 be…
|
CWE-77
Command Injection
|
CVE-2020-11770
|
2024-11-21 13:58 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210062
|
4.8 |
MEDIUM
Network
|
netgear
|
d7800_firmware r7500_firmware r7800_firmware r8900_firmware r9000_firmware rax120_firmware xr500_firmware xr700_firmware rbr20_firmware rbs20_firmware rbk20_firmware …
|
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11769
|
2024-11-21 13:58 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210063
|
4.8 |
MEDIUM
Network
|
netgear
|
d7800_firmware r7500_firmware r7800_firmware r8900_firmware r9000_firmware rax120_firmware xr500_firmware xr700_firmware rbr20_firmware rbs20_firmware rbk20_firmware …
|
Certain NETGEAR devices are affected by Stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11768
|
2024-11-21 13:58 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210064
|
7.5 |
HIGH
Network
|
varnish-cache varnish-software opensuse debian
|
varnish_cache leap backports_sle debian_linux
|
An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There …
|
CWE-617
Reachable Assertion
|
CVE-2020-11653
|
2024-11-21 13:58 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210065
|
7.5 |
HIGH
Network
|
ixsystems
|
freenas_firmware truenas_firmware
|
An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a denial of service. The login authentication component has no limits on the length o…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-11650
|
2024-11-21 13:58 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210066
|
3.1 |
LOW
Network
|
istio envoyproxy
|
istio envoy
|
Istio through 1.5.1 and Envoy through 1.14.1 have a data-leak issue. If there is a TCP connection (negotiated with SNI over HTTPS) to *.example.com, a request for a domain concurrently configured exp…
|
NVD-CWE-noinfo
|
CVE-2020-11767
|
2024-11-21 13:58 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210067
|
5.5 |
MEDIUM
Local
|
xen fedoraproject
|
xen fedora
|
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service because of a bad error path in GNTTABOP_map_grant. Grant table operations are expected to return 0 …
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-11743
|
2024-11-21 13:58 |
2020-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210068
|
5.5 |
MEDIUM
Local
|
xen fedoraproject
|
xen fedora
|
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service because of bad continuation handling in GNTTABOP_copy. Grant table operations are expected to retur…
|
NVD-CWE-Other
|
CVE-2020-11742
|
2024-11-21 13:58 |
2020-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210069
|
8.8 |
HIGH
Local
|
xen fedoraproject debian opensuse
|
xen fedora debian_linux leap
|
An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information about other guests, cause a denial of service, or possibly g…
|
CWE-909
Missing Initialization of Resource
|
CVE-2020-11741
|
2024-11-21 13:58 |
2020-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210070
|
7.8 |
HIGH
Local
|
xen fedoraproject debian opensuse
|
xen fedora debian_linux leap
|
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service or possibly gain privileges because of missing memory barriers in read-write unlock paths. The read…
|
CWE-362
Race Condition
|
CVE-2020-11739
|
2024-11-21 13:58 |
2020-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|