|
196751
|
7.4 |
HIGH
Network
|
nttdata ashikagabank sihd-bk shikokubank tohoku-bank naganobank 77bank hokkaidobank hokugin
|
mypallete ashigin ikeda_senshu_bank shikoku_bank tougin nagagin 77_bank dogin hokuriku_bank_portal
|
Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-misma…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-5523
|
2024-11-21 14:34 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196752
|
7.4 |
HIGH
Network
|
fujixerox
|
easy_netprint
|
The kantan netprint App for Android 2.0.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-5522
|
2024-11-21 14:34 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196753
|
7.4 |
HIGH
Network
|
fujixerox
|
easy_netprint
|
The kantan netprint App for iOS 2.0.2 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a cra…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-5521
|
2024-11-21 14:34 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196754
|
7.4 |
HIGH
Network
|
fujixerox
|
netprint
|
The netprint App for iOS 3.2.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted ce…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-5520
|
2024-11-21 14:34 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196755
|
7.9 |
HIGH
Adjacent
|
philips
|
hue_bridge_v2_firmware
|
Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL string during the commissioning phase, resulting in a remote code…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6007
|
2024-11-21 14:34 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196756
|
5.3 |
MEDIUM
Network
|
vmware oracle
|
spring_framework flexcube_private_banking insurance_policy_administration_j2ee insurance_rules_palette retail_service_backbone retail_back_office weblogic_server application_test…
|
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) …
|
CWE-352
Origin Validation Error
|
CVE-2020-5397
|
2024-11-21 14:34 |
2020-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196757
|
7.5 |
HIGH
Network
|
vmware oracle netapp
|
spring_framework flexcube_private_banking insurance_policy_administration_j2ee insurance_rules_palette retail_service_backbone retail_back_office weblogic_server application_test…
|
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it …
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-5398
|
2024-11-21 14:34 |
2020-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196758
|
6.5 |
MEDIUM
Network
|
phpbb
|
phpbb
|
phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.
|
CWE-352
Origin Validation Error
|
CVE-2020-5502
|
2024-11-21 14:34 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196759
|
4.3 |
MEDIUM
Network
|
phpbb
|
phpbb
|
phpBB 3.2.8 allows a CSRF attack that can modify a group avatar.
|
CWE-352
Origin Validation Error
|
CVE-2020-5501
|
2024-11-21 14:34 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196760
|
7.2 |
HIGH
Network
|
phpgurukul
|
car_rental_portal
|
PHPGurukul Car Rental Project v1.0 allows Remote Code Execution via an executable file in an upload of a new profile image.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-5509
|
2024-11-21 14:34 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|