|
196781
|
6.1 |
MEDIUM
Network
|
mitreid
|
connect
|
The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being included in the page unsanitized. This is related to header.tag. The issue can be ex…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5497
|
2024-11-21 14:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196782
|
8.8 |
HIGH
Network
|
fontforge opensuse
|
fontforge leap
|
FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-5496
|
2024-11-21 14:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196783
|
8.8 |
HIGH
Network
|
fontforge fedoraproject opensuse
|
fontforge fedora leap
|
FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.
|
CWE-416
Use After Free
|
CVE-2020-5395
|
2024-11-21 14:34 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196784
|
5.3 |
MEDIUM
Network
|
ibm
|
safer_payments
|
IBM Counter Fraud Management for Safer Payments 5.7.0.00 through 5.7.0.10, 6.0.0.00 through 6.0.0.07, 6.1.0.00 through 6.1.0.05, and 6.2.0.00 through 6.2.1.00 could allow an authenticated attacker un…
|
NVD-CWE-noinfo
|
CVE-2020-4729
|
2024-11-21 14:33 |
2023-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196785
|
8.2 |
HIGH
Network
|
ibm
|
spectrum_scale
|
A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID…
|
NVD-CWE-noinfo
|
CVE-2020-4927
|
2024-11-21 14:33 |
2023-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196786
|
- |
|
-
|
-
|
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 190837.
|
-
|
CVE-2020-4874
|
2024-11-21 14:33 |
2024-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196787
|
- |
|
-
|
-
|
Minerbabe through V4.16 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io.
|
-
|
CVE-2020-5200
|
2024-11-21 14:33 |
2024-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196788
|
5.3 |
MEDIUM
Network
|
ibm
|
tririga_application_platform
|
IBM TRIRIGA 3.0, 4.0, and 4.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in furt…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-4868
|
2024-11-21 14:33 |
2023-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196789
|
5.5 |
MEDIUM
Local
|
ibm
|
cloud_pak_system
|
IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 191290.
|
-
|
CVE-2020-4914
|
2024-11-21 14:33 |
2023-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196790
|
8.8 |
HIGH
Network
|
ibm
|
financial_transaction_manager
|
IBM Financial Transaction Manager 3.2.0 through 3.2.10 could allow an authenticated user to perform unauthorized actions due to improper validation. IBM X-Force ID: 192954.
|
CWE-20
Improper Input Validation
|
CVE-2020-5002
|
2024-11-21 14:33 |
2023-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|