|
210461
|
4.4 |
MEDIUM
Local
|
linux opensuse canonical netapp
|
linux_kernel leap ubuntu_linux steelstore_cloud_integrated_storage active_iq_unified_manager solidfire hci_management_node aff_a700_firmware h410c_firmware h300s_firmware
|
A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data.
|
-
|
CVE-2020-10732
|
2024-11-21 13:55 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210462
|
7.5 |
HIGH
Network
|
redhat netapp
|
undertow oncommand_insight jboss_enterprise_application_platform openshift_application_runtimes
|
A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-10705
|
2024-11-21 13:55 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210463
|
7.5 |
HIGH
Network
|
inductiveautomation
|
ignition_gateway
|
The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-10644
|
2024-11-21 13:55 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210464
|
8.2 |
HIGH
Network
|
perl fedoraproject opensuse oracle
|
perl fedora leap communications_eagle_lnp_application_processor sd-wan_edge enterprise_manager_base_platform communications_billing_and_revenue_management communications_offline_…
|
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2020-10543
|
2024-11-21 13:55 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210465
|
5.5 |
MEDIUM
Local
|
qemu
|
qemu
|
A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generatio…
|
NVD-CWE-Other
|
CVE-2020-10702
|
2024-11-21 13:55 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210466
|
9.8 |
CRITICAL
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, gr…
|
CWE-89
SQL Injection
|
CVE-2020-10549
|
2024-11-21 13:55 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210467
|
9.8 |
CRITICAL
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, gra…
|
CWE-89
SQL Injection
|
CVE-2020-10548
|
2024-11-21 13:55 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210468
|
9.8 |
CRITICAL
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to late…
|
CWE-89
SQL Injection
|
CVE-2020-10547
|
2024-11-21 13:55 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210469
|
9.8 |
CRITICAL
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral mo…
|
CWE-89
SQL Injection
|
CVE-2020-10546
|
2024-11-21 13:55 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210470
|
6.0 |
MEDIUM
Network
|
linuxfoundation redhat fedoraproject
|
cni_network_plugins enterprise_linux fedora openshift_container_platform
|
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A m…
|
NVD-CWE-Other
|
CVE-2020-10749
|
2024-11-21 13:55 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|