|
196661
|
6.8 |
MEDIUM
Adjacent
|
necplatforms
|
aterm_sa3500g_firmware
|
Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to send a specially crafted request to a specific URL, which may result in an arbitrary command…
|
CWE-78
OS Command
|
CVE-2020-5636
|
2024-11-21 14:34 |
2020-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196662
|
8.8 |
HIGH
Adjacent
|
necplatforms
|
aterm_sa3500g_firmware
|
Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially crafted request to a specific URL, which may result in an arbitrary command executio…
|
CWE-78
OS Command
|
CVE-2020-5635
|
2024-11-21 14:34 |
2020-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196663
|
5.3 |
MEDIUM
Network
|
f5
|
big-ip_advanced_firewall_manager
|
On BIG-IP 14.1.0-14.1.2.6, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user is granted the ad…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5950
|
2024-11-21 14:34 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196664
|
7.5 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system …
|
On BIG-IP versions 14.0.0-14.0.1 and 13.1.0-13.1.3.4, certain traffic pattern sent to a virtual server configured with an FTP profile can cause the FTP channel to break.
|
NVD-CWE-noinfo
|
CVE-2020-5949
|
2024-11-21 14:34 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196665
|
9.6 |
CRITICAL
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system …
|
On BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, undisclosed endpoints in iControl REST allow for a reflected XSS attack, w…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5948
|
2024-11-21 14:34 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196666
|
9.8 |
CRITICAL
Network
|
eat_spray_love_project
|
eat_spray_love
|
The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and retrieve or modify information that they would not normally have access to.
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2020-5800
|
2024-11-21 14:34 |
2020-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196667
|
9.8 |
CRITICAL
Network
|
eat_spray_love_project
|
eat_spray_love
|
The Eat Spray Love mobile app for both iOS and Android contains a backdoor account that, when modified, allowed privileged access to restricted functionality and to other users' data.
|
NVD-CWE-Other
|
CVE-2020-5799
|
2024-11-21 14:34 |
2020-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196668
|
7.8 |
HIGH
Local
|
druva
|
insync
|
inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privileged user due to improper integrity checks and directory permi…
|
CWE-276 CWE-354
Incorrect Default Permissions Improper Validation of Integrity Check Value
|
CVE-2020-5798
|
2024-11-21 14:34 |
2020-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196669
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
gt2107-wtbd_firmware gt2107-wtsd_firmware gt2104-rtbd_firmware gt2104-pmbd_firmware gt2103-pmbd_firmware gs2110-wtbd_firmware gs2107-wtbd_firmware le7-40gu-l_firmware gs2110-w…
|
Out-of-bounds read vulnerability in GT21 model of GOT2000 series (GT2107-WTBD V01.39.000 and earlier, GT2107-WTSD V01.39.000 and earlier, GT2104-RTBD V01.39.000 and earlier, GT2104-PMBD V01.39.000 an…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-5675
|
2024-11-21 14:34 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196670
|
7.8 |
HIGH
Local
|
checkpoint
|
endpoint_security
|
Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-6021
|
2024-11-21 14:34 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|