|
210151
|
2.2 |
LOW
Network
|
freerdp canonical debian
|
freerdp ubuntu_linux debian_linux
|
In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in update_read_synchronize that could lead to a later out-of-bounds read.
|
-
|
CVE-2020-11046
|
2024-11-21 13:56 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210152
|
3.3 |
LOW
Network
|
freerdp debian canonical
|
freerdp debian_linux ubuntu_linux
|
In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in update_read_bitmap_data that allows client memory to be read to an image buffer. The result displayed on screen as colour.
|
-
|
CVE-2020-11045
|
2024-11-21 13:56 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210153
|
2.2 |
LOW
Network
|
freerdp canonical debian
|
freerdp ubuntu_linux debian_linux
|
In FreeRDP greater than 1.2 and before 2.0.0, a double free in update_read_cache_bitmap_v3_order crashes the client application if corrupted data from a manipulated server is parsed. This has been pa…
|
-
|
CVE-2020-11044
|
2024-11-21 13:56 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210154
|
5.9 |
MEDIUM
Network
|
freerdp debian canonical
|
freerdp debian_linux ubuntu_linux
|
In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading a attacker-defined amount of client memory (32bit unsigned -> 4GB) to an inter…
|
-
|
CVE-2020-11042
|
2024-11-21 13:56 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210155
|
7.5 |
HIGH
Network
|
wavlink
|
wl-wn575a3_firmware wl-wn579g3_firmware wn531a6_firmware wn535g3_firmware wn530h4_firmware wn57x93_firmware wn572hg3_firmware wn575a4_firmware wn578a2_firmware wn579g3_firm…
|
An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication i…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-10974
|
2024-11-21 13:56 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210156
|
7.5 |
HIGH
Network
|
wavlink
|
wn530hg4_firmware wn531g3_firmware wn533a8_firmware wn551k1_firmware
|
An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a crafted POST request returns the current configurati…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-10973
|
2024-11-21 13:56 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210157
|
7.5 |
HIGH
Network
|
wavlink
|
wn530hg4_firmware wn531g3_firmware wn572hg3_firmware
|
An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page. No authentication is required in order to reach the page (a ce…
|
CWE-306 CWE-522
Missing Authentication for Critical Function Insufficiently Protected Credentials
|
CVE-2020-10972
|
2024-11-21 13:56 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210158
|
8.8 |
HIGH
Network
|
wavlink
|
wl-wn575a3_firmware wl-wn530hg4_firmware wl-wn579g3_firmware
|
An issue was discovered on Wavlink Jetstream devices where a crafted POST request can be sent to adm.cgi that will result in the execution of the supplied command if there is an active session at the…
|
CWE-20
Improper Input Validation
|
CVE-2020-10971
|
2024-11-21 13:56 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210159
|
5.4 |
MEDIUM
Network
|
glpi-project
|
glpi
|
In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored XSS in the comments of items in the Knowledge base. Adding a comment with conte…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11036
|
2024-11-21 13:56 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210160
|
9.3 |
CRITICAL
Network
|
glpi-project fedoraproject
|
glpi fedora
|
In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values.…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-11035
|
2024-11-21 13:56 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|