|
210391
|
7.8 |
HIGH
Local
|
qualcomm
|
apq8096au_firmware apq8098_firmware bitra_firmware kamorta_firmware msm8917_firmware msm8953_firmware msm8998_firmware qcm2150_firmware qcs405_firmware qcs605_firmware q…
|
u'Calling thread may free the data buffer pointer that was passed to the callback and later when event loop executes the callback, data buffer may not be valid and will lead to use after free scenari…
|
CWE-416
Use After Free
|
CVE-2020-11120
|
2024-11-21 13:56 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210392
|
7.5 |
HIGH
Network
|
qualcomm
|
apq8009_firmware apq8017_firmware apq8053_firmware apq8096au_firmware apq8098_firmware bitra_firmware kamorta_firmware mdm9150_firmware mdm9206_firmware mdm9207c_firmware
|
u'Information exposure issues while processing IE header due to improper check of beacon IE frame' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Con…
|
CWE-20
Improper Input Validation
|
CVE-2020-11118
|
2024-11-21 13:56 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210393
|
9.8 |
CRITICAL
Network
|
qualcomm
|
apq8009_firmware apq8053_firmware apq8096au_firmware apq8098_firmware bitra_firmware kamorta_firmware mdm9206_firmware mdm9207c_firmware mdm9607_firmware mdm9640_firmware
|
u'Possible out of bound write while processing association response received from host due to lack of check of IE length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Conne…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-11116
|
2024-11-21 13:56 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210394
|
7.5 |
HIGH
Network
|
qualcomm
|
apq8009_firmware apq8053_firmware apq8096au_firmware apq8098_firmware bitra_firmware kamorta_firmware mdm9206_firmware mdm9207c_firmware mdm9607_firmware mdm9640_firmware
|
u'Buffer over read occurs while processing information element from beacon due to lack of check of data received from beacon' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics C…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-11115
|
2024-11-21 13:56 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210395
|
5.3 |
MEDIUM
Network
|
oracle redhat
|
virtualization ovirt-engine
|
An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the tar…
|
CWE-601
Open Redirect
|
CVE-2020-10775
|
2024-11-21 13:56 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210396
|
6.3 |
MEDIUM
Network
|
redhat
|
cloudforms_management_engine
|
Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula …
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-10780
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210397
|
8.3 |
HIGH
Network
|
redhat
|
cloudforms
|
Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group can perform actions restricted only to EVM-Super-administrator group, leads to,…
|
NVD-CWE-noinfo
|
CVE-2020-10783
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210398
|
6.5 |
MEDIUM
Network
|
redhat
|
cloudforms
|
Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right cri…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-10779
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210399
|
6.0 |
MEDIUM
Network
|
redhat
|
cloudforms
|
In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This busines…
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2020-10778
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210400
|
5.4 |
MEDIUM
Network
|
redhat
|
cloudforms
|
A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using Clou…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10777
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|