|
210371
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-11668
|
2024-11-21 13:58 |
2020-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210372
|
7.5 |
HIGH
Network
|
castlerock
|
snmpc_online
|
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each request's cookie value.
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2020-11557
|
2024-11-21 13:58 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210373
|
5.4 |
MEDIUM
Network
|
castlerock
|
snmpc_online
|
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There are multiple persistent (stored) and reflected XSS vulnerabilities.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11556
|
2024-11-21 13:58 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210374
|
7.5 |
HIGH
Network
|
castlerock
|
snmpc_online
|
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive credential information from backup files.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-11555
|
2024-11-21 13:58 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210375
|
7.5 |
HIGH
Network
|
castlerock
|
snmpc_online
|
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive information via info.php4.
|
NVD-CWE-noinfo
|
CVE-2020-11554
|
2024-11-21 13:58 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210376
|
8.8 |
HIGH
Network
|
castlerock
|
snmpc_online
|
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There is pervasive CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-11553
|
2024-11-21 13:58 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210377
|
4.8 |
MEDIUM
Network
|
netgear
|
d7800_firmware r7500_firmware r7800_firmware r8900_firmware r9000_firmware rax120_firmware xr500_firmware xr700_firmware rbr20_firmware rbs20_firmware rbk20_firmware …
|
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11775
|
2024-11-21 13:58 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210378
|
8.8 |
HIGH
Network
|
netgear
|
d6220_firmware d6400_firmware d8500_firmware r6220_firmware r6250_firmware r6260_firmware r6400_firmware r6700_firmware r6800_firmware r6900_firmware r6900p_firmware …
|
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000v2 before 1.0.0.53, D8500 before 1.0.3.44, R6220 be…
|
CWE-77
Command Injection
|
CVE-2020-11770
|
2024-11-21 13:58 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210379
|
4.8 |
MEDIUM
Network
|
netgear
|
d7800_firmware r7500_firmware r7800_firmware r8900_firmware r9000_firmware rax120_firmware xr500_firmware xr700_firmware rbr20_firmware rbs20_firmware rbk20_firmware …
|
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11769
|
2024-11-21 13:58 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210380
|
4.8 |
MEDIUM
Network
|
netgear
|
d7800_firmware r7500_firmware r7800_firmware r8900_firmware r9000_firmware rax120_firmware xr500_firmware xr700_firmware rbr20_firmware rbs20_firmware rbk20_firmware …
|
Certain NETGEAR devices are affected by Stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11768
|
2024-11-21 13:58 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|