|
209771
|
9.8 |
CRITICAL
Network
|
pepperl-fuchs korenix
|
es7510-xt_firmware es8509-xt_firmware es8510-xt_firmware es9528-xtv2_firmware es7506_firmware es7510_firmware es7528_firmware es8508_firmware es8508f_firmware es8510_firmwa…
|
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-X…
|
-
|
CVE-2020-12501
|
2024-11-21 13:59 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209772
|
9.8 |
CRITICAL
Network
|
pepperl-fuchs
|
es7510-xt_firmware es8509-xt_firmware es8510-xt_firmware es9528-xtv2_firmware es7506_firmware es7510_firmware es7528_firmware es8508_firmware es8508f_firmware es8510_firmwa…
|
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-X…
|
-
|
CVE-2020-12500
|
2024-11-21 13:59 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209773
|
4.7 |
MEDIUM
Local
|
mozilla
|
firefox
|
During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-12401
|
2024-11-21 13:59 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209774
|
4.7 |
MEDIUM
Local
|
mozilla
|
firefox
|
When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects F…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-12400
|
2024-11-21 13:59 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209775
|
7.8 |
HIGH
Local
|
intel
|
driver_\&_support_assistant
|
Improper permissions in the Intel(R) Driver & Support Assistant before version 20.7.26.7 may allow an authenticated user to potentially enable escalation of privilege via local access.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-12302
|
2024-11-21 13:59 |
2020-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209776
|
7.5 |
HIGH
Network
|
wavlink
|
wn530h4_firmware
|
An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to leak router settings, including cleartext login d…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-12127
|
2024-11-21 13:59 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209777
|
9.8 |
CRITICAL
Network
|
wavlink
|
wn530h4_firmware
|
Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to leak router settings, change configuration variables, and cause…
|
CWE-287
Improper Authentication
|
CVE-2020-12126
|
2024-11-21 13:59 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209778
|
9.8 |
CRITICAL
Network
|
wavlink
|
wn530h4_firmware
|
A remote buffer overflow vulnerability in the /cgi-bin/makeRequest.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary machine instructions as root without …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-12125
|
2024-11-21 13:59 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209779
|
9.8 |
CRITICAL
Network
|
wavlink
|
wn530h4_firmware
|
A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without au…
|
CWE-78
OS Command
|
CVE-2020-12124
|
2024-11-21 13:59 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209780
|
8.1 |
HIGH
Network
|
wavlink
|
wn530h4_firmware
|
CSRF vulnerabilities in the /cgi-bin/ directory of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to remotely access router endpoints, because these endpoints do not contain CSRF tokens. If…
|
CWE-352
Origin Validation Error
|
CVE-2020-12123
|
2024-11-21 13:59 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|