|
210381
|
7.5 |
HIGH
Network
|
varnish-cache varnish-software opensuse debian
|
varnish_cache leap backports_sle debian_linux
|
An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There …
|
CWE-617
Reachable Assertion
|
CVE-2020-11653
|
2024-11-21 13:58 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210382
|
7.5 |
HIGH
Network
|
ixsystems
|
freenas_firmware truenas_firmware
|
An issue was discovered in iXsystems FreeNAS (and TrueNAS) 11.2 before 11.2-u8 and 11.3 before 11.3-U1. It allows a denial of service. The login authentication component has no limits on the length o…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-11650
|
2024-11-21 13:58 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210383
|
3.1 |
LOW
Network
|
istio envoyproxy
|
istio envoy
|
Istio through 1.5.1 and Envoy through 1.14.1 have a data-leak issue. If there is a TCP connection (negotiated with SNI over HTTPS) to *.example.com, a request for a domain concurrently configured exp…
|
NVD-CWE-noinfo
|
CVE-2020-11767
|
2024-11-21 13:58 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210384
|
5.5 |
MEDIUM
Local
|
xen fedoraproject
|
xen fedora
|
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service because of a bad error path in GNTTABOP_map_grant. Grant table operations are expected to return 0 …
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-11743
|
2024-11-21 13:58 |
2020-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210385
|
5.5 |
MEDIUM
Local
|
xen fedoraproject
|
xen fedora
|
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service because of bad continuation handling in GNTTABOP_copy. Grant table operations are expected to retur…
|
NVD-CWE-Other
|
CVE-2020-11742
|
2024-11-21 13:58 |
2020-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210386
|
8.8 |
HIGH
Local
|
xen fedoraproject debian opensuse
|
xen fedora debian_linux leap
|
An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information about other guests, cause a denial of service, or possibly g…
|
CWE-909
Missing Initialization of Resource
|
CVE-2020-11741
|
2024-11-21 13:58 |
2020-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210387
|
7.8 |
HIGH
Local
|
xen fedoraproject debian opensuse
|
xen fedora debian_linux leap
|
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service or possibly gain privileges because of missing memory barriers in read-write unlock paths. The read…
|
CWE-362
Race Condition
|
CVE-2020-11739
|
2024-11-21 13:58 |
2020-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210388
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
snd_ctl_elem_add in sound/core/control.c in the Linux kernel through 5.6.3 has a count=info->owner line, which later affects a private_size*count multiplication for unspecified "interesting side effe…
|
NVD-CWE-noinfo
|
CVE-2020-11725
|
2024-11-21 13:58 |
2020-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210389
|
9.8 |
CRITICAL
Network
|
konghq
|
docker-kong
|
An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces other than 127.0.0.1. NOTE: The vendor argue that this CVE is not a vulnerability b…
|
NVD-CWE-Other
|
CVE-2020-11710
|
2024-11-21 13:58 |
2020-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210390
|
5.3 |
MEDIUM
Network
|
argoproj
|
argo_cd
|
Fixed in v1.5.1, Argo version v1.5.0 was vulnerable to a user-enumeration vulnerability which allowed attackers to determine the usernames of valid (non-SSO) accounts because /api/v1/session returned…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-11576
|
2024-11-21 13:58 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|