|
210201
|
8.8 |
HIGH
Network
|
silver-peak
|
unity_orchestrator
|
In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unauthorized MySQL queries against the Orchestrator database using the /sqlExecution R…
|
CWE-22
Path Traversal
|
CVE-2020-12147
|
2024-11-21 13:59 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210202
|
8.8 |
HIGH
Network
|
silver-peak
|
unity_orchestrator
|
In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can access, modify, and delete restricted files on the Orchestrator server using the/debugFiles…
|
CWE-22
Path Traversal
|
CVE-2020-12146
|
2024-11-21 13:59 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210203
|
9.8 |
CRITICAL
Network
|
silver-peak
|
unity_orchestrator
|
Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API calls from localhost. This makes it possible to log in to Orchestrator by intr…
|
CWE-287
Improper Authentication
|
CVE-2020-12145
|
2024-11-21 13:59 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210204
|
9.8 |
CRITICAL
Network
|
pepperl-fuchs korenix westermo
|
es7510-xt_firmware es8509-xt_firmware es8510-xt_firmware es9528-xtv2_firmware es7506_firmware es7510_firmware es7528_firmware es8508_firmware es8508f_firmware es8510_firmwa…
|
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-X…
|
-
|
CVE-2020-12504
|
2024-11-21 13:59 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210205
|
7.2 |
HIGH
Network
|
pepperl-fuchs korenix
|
es7510-xt_firmware es8509-xt_firmware es8510-xt_firmware es9528-xtv2_firmware es7506_firmware es7510_firmware es7528_firmware es8508_firmware es8508f_firmware es8510_firmwa…
|
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-X…
|
-
|
CVE-2020-12503
|
2024-11-21 13:59 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210206
|
8.8 |
HIGH
Network
|
pepperl-fuchs korenix
|
es7510-xt_firmware es8509-xt_firmware es8510-xt_firmware es9528-xtv2_firmware es7506_firmware es7510_firmware es7528_firmware es8508_firmware es8508f_firmware es8510_firmwa…
|
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-X…
|
-
|
CVE-2020-12502
|
2024-11-21 13:59 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210207
|
9.8 |
CRITICAL
Network
|
pepperl-fuchs korenix
|
es7510-xt_firmware es8509-xt_firmware es8510-xt_firmware es9528-xtv2_firmware es7506_firmware es7510_firmware es7528_firmware es8508_firmware es8508f_firmware es8510_firmwa…
|
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-X…
|
-
|
CVE-2020-12501
|
2024-11-21 13:59 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210208
|
9.8 |
CRITICAL
Network
|
pepperl-fuchs
|
es7510-xt_firmware es8509-xt_firmware es8510-xt_firmware es9528-xtv2_firmware es7506_firmware es7510_firmware es7528_firmware es8508_firmware es8508f_firmware es8510_firmwa…
|
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-X…
|
-
|
CVE-2020-12500
|
2024-11-21 13:59 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210209
|
4.7 |
MEDIUM
Local
|
mozilla
|
firefox
|
During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-12401
|
2024-11-21 13:59 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210210
|
4.7 |
MEDIUM
Local
|
mozilla
|
firefox
|
When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects F…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-12400
|
2024-11-21 13:59 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|