|
198231
|
6.1 |
MEDIUM
Network
|
digisol
|
dg-hr3400_firmware
|
Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date module and "Keyword" in URL Filter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35262
|
2024-11-21 14:27 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198232
|
7.5 |
HIGH
Network
|
nxlog
|
nxlog
|
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a crafted Syslog payload to the Syslog service. Thi…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-35488
|
2024-11-21 14:27 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198233
|
9.8 |
CRITICAL
Network
|
asus
|
dsl-n17u_firmware
|
The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication via a POST request to Advanced_System_Content.asp wi…
|
CWE-287
Improper Authentication
|
CVE-2020-35219
|
2024-11-21 14:27 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198234
|
5.5 |
MEDIUM
Local
|
gnu redhat netapp broadcom
|
binutils enterprise_linux hci_compute_node_firmware cloud_backup ontap_select_deploy_administration_utility solidfire_\&_hci_management_node solidfire\ _enterprise_sds_\&…
|
There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to caus…
|
-
|
CVE-2020-35507
|
2024-11-21 14:27 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198235
|
5.5 |
MEDIUM
Local
|
gnu fedoraproject netapp broadcom
|
binutils fedora cloud_backup ontap_select_deploy_administration_utility solidfire_\&_hci_management_node solidfire\ _enterprise_sds_\&_hci_storage_node brocade_fabric_ope…
|
There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereferen…
|
-
|
CVE-2020-35496
|
2024-11-21 14:27 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198236
|
5.5 |
MEDIUM
Local
|
gnu fedoraproject netapp broadcom
|
binutils fedora cloud_backup ontap_select_deploy_administration_utility solidfire_\&_hci_management_node solidfire\ _enterprise_sds_\&_hci_storage_node brocade_fabric_ope…
|
There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from t…
|
-
|
CVE-2020-35495
|
2024-11-21 14:27 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198237
|
6.1 |
MEDIUM
Local
|
gnu fedoraproject netapp broadcom
|
binutils fedora cloud_backup ontap_select_deploy_administration_utility solidfire_\&_hci_management_node solidfire\ _enterprise_sds_\&_hci_storage_node brocade_fabric_ope…
|
There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to…
|
-
|
CVE-2020-35494
|
2024-11-21 14:27 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198238
|
5.5 |
MEDIUM
Local
|
gnu fedoraproject netapp broadcom
|
binutils fedora cloud_backup ontap_select_deploy_administration_utility solidfire_\&_hci_management_node solidfire\ _enterprise_sds_\&_hci_storage_node brocade_fabric_ope…
|
A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an imp…
|
-
|
CVE-2020-35493
|
2024-11-21 14:27 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198239
|
9.0 |
CRITICAL
Network
|
electronjs
|
zonote
|
zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).
|
CWE-79
Cross-site Scripting
|
CVE-2020-35717
|
2024-11-21 14:27 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198240
|
6.5 |
MEDIUM
Adjacent
|
tenda
|
f3_firmware
|
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2020-35391
|
2024-11-21 14:27 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|