|
200271
|
7.8 |
HIGH
Local
|
linux fedoraproject debian netapp broadcom oracle
|
linux_kernel fedora debian_linux active_iq_unified_manager fabric_operating_system solidfire_baseboard_management_controller_firmware h410c_firmware a700s_firmware 8300_firmwa…
|
A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b.
|
CWE-416 CWE-667
Use After Free Improper Locking
|
CVE-2020-29661
|
2024-11-21 14:24 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200272
|
4.4 |
MEDIUM
Local
|
linux fedoraproject debian netapp broadcom
|
linux_kernel fedora debian_linux active_iq_unified_manager fabric_operating_system solidfire_baseboard_management_controller_firmware h410c_firmware a700s_firmware 8300_firmwa…
|
A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIO…
|
CWE-416 CWE-667
Use After Free Improper Locking
|
CVE-2020-29660
|
2024-11-21 14:24 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200273
|
9.1 |
CRITICAL
Network
|
jerryscript
|
jerryscript
|
In JerryScript 2.3.0, there is an out-of-bounds read in main_print_unhandled_exception in the main-utils.c file.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-29657
|
2024-11-21 14:24 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200274
|
7.5 |
HIGH
Network
|
asus
|
rt-ac88u_firmware
|
An information disclosure vulnerability exists in RT-AC88U Download Master before 3.1.0.108. A direct access to /downloadmaster/dm_apply.cgi?action_mode=initial&download_type=General&special_cgi=get_…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2020-29656
|
2024-11-21 14:24 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200275
|
7.5 |
HIGH
Network
|
asus
|
rt-ac88u_firmware
|
An injection vulnerability exists in RT-AC88U Download Master before 3.1.0.108. Accessing Main_Login.asp?flag=1&productname=FOOBAR&url=/downloadmaster/task.asp will redirect to the login site, which …
|
CWE-74
Injection
|
CVE-2020-29655
|
2024-11-21 14:24 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200276
|
7.5 |
HIGH
Network
|
pytest fedoraproject oracle
|
py fedora zfs_storage_appliance_kit
|
A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying …
|
NVD-CWE-Other
|
CVE-2020-29651
|
2024-11-21 14:24 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200277
|
9.8 |
CRITICAL
Network
|
irssi
|
docker_image
|
The official irssi docker images before 1.1-alpine (Alpine specific) contain a blank password for a root user. System using the irssi docker container deployed by affected versions of the Docker imag…
|
NVD-CWE-Other
|
CVE-2020-29602
|
2024-11-21 14:24 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200278
|
9.8 |
CRITICAL
Network
|
docker
|
notary_docker_image
|
The official notary docker images before signer-0.6.1-1 contain a blank password for a root user. System using the notary docker container deployed by affected versions of the docker image may allow …
|
NVD-CWE-Other
|
CVE-2020-29601
|
2024-11-21 14:24 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200279
|
9.8 |
CRITICAL
Network
|
docker
|
spiped_alpine_docker_image
|
The official spiped docker images before 1.5-alpine contain a blank password for a root user. Systems using the spiped docker container deployed by affected versions of the docker image may allow an …
|
NVD-CWE-Other
|
CVE-2020-29581
|
2024-11-21 14:24 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200280
|
9.8 |
CRITICAL
Network
|
docker
|
storm_docker_image
|
The official storm Docker images before 1.2.1 contain a blank password for a root user. Systems using the Storm Docker container deployed by affected versions of the Docker image may allow an remote …
|
NVD-CWE-Other
|
CVE-2020-29580
|
2024-11-21 14:24 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|