|
196981
|
7.5 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system …
|
On BIG-IP versions 14.0.0-14.0.1 and 13.1.0-13.1.3.4, certain traffic pattern sent to a virtual server configured with an FTP profile can cause the FTP channel to break.
|
NVD-CWE-noinfo
|
CVE-2020-5949
|
2024-11-21 14:34 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196982
|
9.6 |
CRITICAL
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system …
|
On BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, undisclosed endpoints in iControl REST allow for a reflected XSS attack, w…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5948
|
2024-11-21 14:34 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196983
|
9.8 |
CRITICAL
Network
|
eat_spray_love_project
|
eat_spray_love
|
The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and retrieve or modify information that they would not normally have access to.
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2020-5800
|
2024-11-21 14:34 |
2020-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196984
|
9.8 |
CRITICAL
Network
|
eat_spray_love_project
|
eat_spray_love
|
The Eat Spray Love mobile app for both iOS and Android contains a backdoor account that, when modified, allowed privileged access to restricted functionality and to other users' data.
|
NVD-CWE-Other
|
CVE-2020-5799
|
2024-11-21 14:34 |
2020-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196985
|
7.8 |
HIGH
Local
|
druva
|
insync
|
inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privileged user due to improper integrity checks and directory permi…
|
CWE-276 CWE-354
Incorrect Default Permissions Improper Validation of Integrity Check Value
|
CVE-2020-5798
|
2024-11-21 14:34 |
2020-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196986
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
gt2107-wtbd_firmware gt2107-wtsd_firmware gt2104-rtbd_firmware gt2104-pmbd_firmware gt2103-pmbd_firmware gs2110-wtbd_firmware gs2107-wtbd_firmware le7-40gu-l_firmware gs2110-w…
|
Out-of-bounds read vulnerability in GT21 model of GOT2000 series (GT2107-WTBD V01.39.000 and earlier, GT2107-WTSD V01.39.000 and earlier, GT2104-RTBD V01.39.000 and earlier, GT2104-PMBD V01.39.000 an…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-5675
|
2024-11-21 14:34 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196987
|
7.8 |
HIGH
Local
|
checkpoint
|
endpoint_security
|
Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-6021
|
2024-11-21 14:34 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196988
|
9.8 |
CRITICAL
Network
|
valvesoftware
|
game_networking_sockets
|
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment() when configured to support plain-text messages, leading …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6017
|
2024-11-21 14:34 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196989
|
7.5 |
HIGH
Network
|
ec-cube
|
ec-cube
|
Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vector.
|
CWE-20
Improper Input Validation
|
CVE-2020-5680
|
2024-11-21 14:34 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196990
|
6.1 |
MEDIUM
Network
|
ec-cube
|
ec-cube
|
Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking attacks. If a user accesses a specially crafted page while logged into the administ…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-5679
|
2024-11-21 14:34 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|