|
209811
|
9.8 |
CRITICAL
Network
|
stengg
|
vpncrypt_m10_firmware
|
The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing credentials of the Admini…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-12106
|
2024-11-21 13:59 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209812
|
7.5 |
HIGH
Network
|
dovecot debian fedoraproject canonical
|
dovecot debian_linux fedora ubuntu_linux
|
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply ne…
|
CWE-674
Uncontrolled Recursion
|
CVE-2020-12100
|
2024-11-21 13:59 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209813
|
7.5 |
HIGH
Network
|
apache
|
wicket fortress
|
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually r…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2020-11976
|
2024-11-21 13:59 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209814
|
7.5 |
HIGH
Network
|
apache netapp canonical opensuse debian fedoraproject oracle
|
http_server clustered_data_ontap ubuntu_linux leap debian_linux fedora instantis_enterprisetrack hyperion_infrastructure_technology enterprise_manager_ops_center communicat…
|
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing con…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-11993
|
2024-11-21 13:59 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209815
|
5.3 |
MEDIUM
Network
|
apache
|
http_server
|
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for lo…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-11985
|
2024-11-21 13:59 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209816
|
9.8 |
CRITICAL
Network
|
apache netapp canonical debian fedoraproject opensuse oracle
|
http_server clustered_data_ontap ubuntu_linux debian_linux fedora leap instantis_enterprisetrack hyperion_infrastructure_technology enterprise_manager_ops_center communicat…
|
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-11984
|
2024-11-21 13:59 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209817
|
9.8 |
CRITICAL
Network
|
ivanti
|
service_manager_heat_remote_control desktop\&server_management
|
Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ agent. The DoS can be triggered by sending a speci…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-12441
|
2024-11-21 13:59 |
2020-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209818
|
7.5 |
HIGH
Network
|
flexera
|
flexnet_publisher
|
An information disclosure vulnerability has been identified in FlexNet Publisher lmadmin.exe 11.14.0.2. The web portal link can be used to access to system files or other important files on the syste…
|
NVD-CWE-noinfo
|
CVE-2020-12081
|
2024-11-21 13:59 |
2020-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209819
|
7.8 |
HIGH
Local
|
pi-hole
|
pi-hole
|
Pi-hole 4.4 allows a user able to write to /etc/pihole/dns-servers.conf to escalate privileges through command injection (shell metacharacters after an IP address).
|
CWE-78
OS Command
|
CVE-2020-12620
|
2024-11-21 13:59 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209820
|
9.8 |
CRITICAL
Network
|
trusteddomain fedoraproject debian
|
opendmarc fedora debian_linux
|
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a spe…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12460
|
2024-11-21 13:59 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|