|
197001
|
4.3 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_advanced_web_application_firewall big-ip_analytics big-ip_application_acceleration_manager big-ip_application_secur…
|
In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able to obtain TCP sequence numbers from the BIG-IP system that can be reused in future connections with …
|
NVD-CWE-noinfo
|
CVE-2020-5947
|
2024-11-21 14:34 |
2020-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197002
|
9.8 |
CRITICAL
Network
|
valvesoftware
|
game_networking_sockets
|
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_ReceiveUnreliableSegment(), leading to a Heap-Based Buffer Underfl…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6016
|
2024-11-21 14:34 |
2020-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197003
|
9.8 |
CRITICAL
Network
|
riken
|
xoonips
|
Deserialization of untrusted data vulnerability in XooNIps 3.49 and earlier allows remote attackers to execute arbitrary code via unspecified vectors.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-5664
|
2024-11-21 14:34 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197004
|
5.4 |
MEDIUM
Network
|
riken
|
xoonips
|
Stored cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5663
|
2024-11-21 14:34 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197005
|
5.4 |
MEDIUM
Network
|
riken
|
xoonips
|
Reflected cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5662
|
2024-11-21 14:34 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197006
|
8.8 |
HIGH
Network
|
riken
|
xoonips
|
SQL injection vulnerability in the XooNIps 3.49 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2020-5659
|
2024-11-21 14:34 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197007
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
melsec_iq-r00_firmware melsec_iq-r01_firmware melsec_iq-r02_firmware melsec_iq-r04_firmware melsec_iq-r16_firmware melsec_iq-r08_firmware melsec_iq-r32_firmware melsec_iq-r120_fi…
|
Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/08/16/32/120(EN)CPU Firmware versions from '35' to '51') al…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-5666
|
2024-11-21 14:34 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197008
|
7.8 |
HIGH
Local
|
nagios
|
nagios_xi
|
Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, resulting in low-privileged users being able to write to…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-5796
|
2024-11-21 14:34 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197009
|
7.5 |
HIGH
Network
|
valvesoftware
|
game_networking_sockets
|
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConnectionTransportUDPBase::Received_Data(), leading to an exception thrown from li…
|
NVD-CWE-noinfo
|
CVE-2020-6019
|
2024-11-21 14:34 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197010
|
7.8 |
HIGH
Local
|
nvidia
|
geforce_now
|
NVIDIA GeForce NOW application software on Windows, all versions prior to 2.0.25.119, contains a vulnerability in its open-source software dependency in which the OpenSSL library is vulnerable to bin…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-5992
|
2024-11-21 14:34 |
2020-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|