|
198341
|
8.8 |
HIGH
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can be reused until a new token is generated, which all…
|
CWE-384
Session Fixation
|
CVE-2020-35229
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198342
|
4.8 |
MEDIUM
Network
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
A cross-site scripting (XSS) vulnerability in the administration web panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote attackers to inject arbitrary web script or HTML via the langua…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35228
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198343
|
7.2 |
HIGH
Network
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the administration web panel) allows an attacker to inject IP addresses into the white…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-35227
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198344
|
7.1 |
HIGH
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sending the corresponding write request command.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-35226
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198345
|
6.8 |
MEDIUM
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was not properly validating the length of string parameters sent in write requests, potentially allowing denial of serv…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-35225
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198346
|
6.5 |
MEDIUM
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
A buffer overflow vulnerability in the NSDP protocol authentication method on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote unauthenticated attackers to force a device reboot.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-35224
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198347
|
8.8 |
HIGH
Network
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices could be bypassed by omitting the CSRF token parameter in HTTP requests.
|
CWE-352
Origin Validation Error
|
CVE-2020-35223
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198348
|
8.8 |
HIGH
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
The hashing algorithm implemented for NSDP password authentication on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was found to be insecure, allowing attackers (with access to a network capture) to qu…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-35221
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198349
|
7.8 |
HIGH
Local
|
libtiff debian fedoraproject netapp redhat
|
libtiff debian_linux fedora ontap_select_deploy_administration_utility enterprise_linux
|
A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threa…
|
-
|
CVE-2020-35524
|
2024-11-21 14:27 |
2021-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198350
|
7.8 |
HIGH
Local
|
libtiff debian netapp redhat
|
libtiff debian_linux ontap_select_deploy_administration_utility enterprise_linux
|
An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The high…
|
-
|
CVE-2020-35523
|
2024-11-21 14:27 |
2021-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|