|
210691
|
7.8 |
HIGH
Local
|
zephyrproject
|
zephyr
|
Multiple syscalls with insufficient argument validation See NCC-ZEP-006 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versions. version 2.1.0 and later versions.
|
CWE-20
Improper Input Validation
|
CVE-2020-10028
|
2024-11-21 13:54 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210692
|
7.8 |
HIGH
Local
|
zephyrproject
|
zephyr
|
An attacker who has obtained code execution within a user thread is able to elevate privileges to that of the kernel. See NCC-ZEP-001 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and …
|
CWE-697
Incorrect Comparison
|
CVE-2020-10027
|
2024-11-21 13:54 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210693
|
7.8 |
HIGH
Local
|
zephyrproject
|
zephyr
|
The arm platform-specific code uses a signed integer comparison when validating system call numbers. An attacker who has obtained code execution within a user thread is able to elevate privileges to …
|
CWE-697
Incorrect Comparison
|
CVE-2020-10024
|
2024-11-21 13:54 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210694
|
6.8 |
MEDIUM
Physics
|
zephyrproject
|
zephyr
|
The shell subsystem contains a buffer overflow, whereby an adversary with physical access to the device is able to cause a memory corruption, resulting in denial of service or possibly code execution…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-10023
|
2024-11-21 13:54 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210695
|
9.8 |
CRITICAL
Network
|
zephyrproject
|
zephyr
|
A malformed JSON payload that is received from an UpdateHub server may trigger memory corruption in the Zephyr OS. This could result in a denial of service in the best case, or code execution in the …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-10022
|
2024-11-21 13:54 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210696
|
7.8 |
HIGH
Local
|
zephyrproject
|
zephyr
|
Out-of-bounds Write in the USB Mass Storage memoryWrite handler with unaligned Sizes See NCC-ZEP-024, NCC-ZEP-025, NCC-ZEP-026 This issue affects: zephyrproject-rtos zephyr version 1.14.1 and later v…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10021
|
2024-11-21 13:54 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210697
|
7.8 |
HIGH
Local
|
zephyrproject
|
zephyr
|
USB DFU has a potential buffer overflow where the requested length (wLength) is not checked against the buffer size. This could be used by a malicious USB host to exploit the buffer overflow. See NCC…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-10019
|
2024-11-21 13:54 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210698
|
9.8 |
CRITICAL
Network
|
assaabloy
|
yale_wipc-301w_firmware
|
ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands.
|
CWE-94
Code Injection
|
CVE-2020-10176
|
2024-11-21 13:54 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210699
|
7.5 |
HIGH
Network
|
doorkeeper_project
|
doorkeeper
|
Doorkeeper version 5.0.0 and later contains an information disclosure vulnerability that allows an attacker to retrieve the client secret only intended for the OAuth application owner. After authoriz…
|
CWE-862
Missing Authorization
|
CVE-2020-10187
|
2024-11-21 13:54 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210700
|
5.4 |
MEDIUM
Network
|
lexmark
|
cs31x_firmware cs41x_firmware cs51x_firmware cx310_firmware cx410_firmware xc2130_firmware cx510_firmware xc2132_firmware ms310_firmware ms312_firmware ms317_firmware
|
A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 before LW74.GM2.P273; CX410 & XC2130 before LW74.GM4.P2…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10094
|
2024-11-21 13:54 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|