|
196761
|
7.5 |
HIGH
Network
|
dovecot fedoraproject
|
dovecot fedora
|
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login in…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-7046
|
2024-11-21 14:36 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196762
|
7.5 |
HIGH
Network
|
opensuse
|
wicked
|
An ni_dhcp4_fsm_process_dhcp4_packet memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets with a different client-id.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-7217
|
2024-11-21 14:36 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196763
|
9.1 |
CRITICAL
Network
|
php tenable oracle opensuse debian
|
php tenable.sc communications_diameter_signaling_router leap debian_linux
|
When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause functi…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-7060
|
2024-11-21 14:36 |
2020-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196764
|
9.1 |
CRITICAL
Network
|
php tenable oracle opensuse debian
|
php tenable.sc communications_diameter_signaling_router leap debian_linux
|
When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-7059
|
2024-11-21 14:36 |
2020-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196765
|
9.8 |
CRITICAL
Network
|
bosch
|
bosch_video_management_system_mobile_video_service divar_ip_3000_firmware divar_ip_7000_firmware
|
Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch BVMS versions 10.0 …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-6770
|
2024-11-21 14:36 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196766
|
7.5 |
HIGH
Network
|
bosch
|
video_management_system_viewer video_management_system
|
A path traversal vulnerability in the Bosch Video Management System (BVMS) NoTouch deployment allows an unauthenticated remote attacker to read arbitrary files from the Central Server. This affects B…
|
CWE-22
Path Traversal
|
CVE-2020-6768
|
2024-11-21 14:36 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196767
|
9.1 |
CRITICAL
Network
|
bosch
|
video_streaming_gateway divar_ip_2000_firmware divar_ip_5000_firmware
|
Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set arbitrary configuration data of the Video Streami…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-6769
|
2024-11-21 14:36 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196768
|
9.8 |
CRITICAL
Network
|
schmid-telecom
|
zi_620_v400_firmware
|
Schmid ZI 620 V400 VPN 090 routers allow an attacker to execute OS commands as root via shell metacharacters to an entry on the SSH subcommand menu, as demonstrated by ping.
|
CWE-78
OS Command
|
CVE-2020-6760
|
2024-11-21 14:36 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196769
|
6.5 |
MEDIUM
Network
|
sos-berlin
|
jobscheduler
|
An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allows attackers to read files from the server via an entity declaration in any of t…
|
CWE-776
XML Entity Expansion
|
CVE-2020-6856
|
2024-11-21 14:36 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196770
|
6.5 |
MEDIUM
Network
|
sos-berlin
|
jobscheduler
|
A large or infinite loop vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to parameterize housekeeping jobs in a way that exhausts system resources and …
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-6855
|
2024-11-21 14:36 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|