|
210141
|
6.8 |
MEDIUM
Network
|
arubanetworks
|
edgeconnect_enterprise
|
The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequent shell command, al…
|
CWE-78
OS Command
|
CVE-2020-12149
|
2024-11-21 13:59 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210142
|
6.8 |
MEDIUM
Network
|
arubanetworks
|
edgeconnect_enterprise
|
A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web serv…
|
CWE-78
OS Command
|
CVE-2020-12148
|
2024-11-21 13:59 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210143
|
4.9 |
MEDIUM
Network
|
broadcom
|
symantec_messaging_gateway
|
An information disclosure flaw allows a malicious, authenticated, privileged web UI user to obtain a password for a remote SCP backup server that they might not otherwise be authorized to access. Thi…
|
NVD-CWE-noinfo
|
CVE-2020-12595
|
2024-11-21 13:59 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210144
|
7.2 |
HIGH
Network
|
broadcom
|
symantec_messaging_gateway
|
A privilege escalation flaw allows a malicious, authenticated, privileged CLI user to escalate their privileges on the system and gain full control over the SMG appliance. This affects SMG prior to 1…
|
NVD-CWE-noinfo
|
CVE-2020-12594
|
2024-11-21 13:59 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210145
|
7.5 |
HIGH
Network
|
wago
|
750-352_firmware 750-831_firmware 750-852_firmware 750-880_firmware 750-881_firmware 750-889_firmware 750-331_firmware 750-829_firmware 750-882_firmware 750-885_firmware
|
Older firmware versions (FW1 up to FW10) of the WAGO PLC family 750-88x and 750-352 are vulnerable for a special denial of service attack.
|
NVD-CWE-noinfo
|
CVE-2020-12516
|
2024-11-21 13:59 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210146
|
7.5 |
HIGH
Network
|
phoenixcontact
|
btp_2043w_firmware btp_2070w_firmware btp_2102w_firmware
|
Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W in all versions to become unresponsive and not accurately update the display co…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-12524
|
2024-11-21 13:59 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210147
|
3.3 |
LOW
Local
|
apache
|
cordova
|
We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially craft…
|
NVD-CWE-noinfo
|
CVE-2020-11990
|
2024-11-21 13:59 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210148
|
5.4 |
MEDIUM
Network
|
intelbras
|
tip200_firmware tip200lite_firmware tip300_firmware
|
Intelbras TIP200 60.61.75.15, TIP200LITE 60.61.75.15, and TIP300 65.61.75.15 devices allow /cgi-bin/cgiServer.exx?page= XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12262
|
2024-11-21 13:59 |
2020-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210149
|
6.5 |
MEDIUM
Adjacent
|
linux
|
linux_kernel
|
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
|
CWE-909
Missing Initialization of Resource
|
CVE-2020-12352
|
2024-11-21 13:59 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210150
|
8.8 |
HIGH
Adjacent
|
linux
|
linux_kernel
|
Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
|
CWE-20
Improper Input Validation
|
CVE-2020-12351
|
2024-11-21 13:59 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|