|
210441
|
6.5 |
MEDIUM
Network
|
redhat canonical
|
openstack-cinder ubuntu_linux
|
An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before openstack-cinder 15.2.0 and all openstack-cinder 16…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-10755
|
2024-11-21 13:56 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210442
|
5.0 |
MEDIUM
Network
|
qemu redhat opensuse canonical
|
qemu enterprise_linux leap ubuntu_linux
|
An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near th…
|
CWE-617
Reachable Assertion
|
CVE-2020-10761
|
2024-11-21 13:56 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210443
|
7.8 |
HIGH
Local
|
linux opensuse redhat fedoraproject debian canonical netapp
|
linux_kernel leap enterprise_linux enterprise_mrg fedora debian_linux ubuntu_linux cloud_backup steelstore_cloud_integrated_storage active_iq_unified_manager
|
A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privi…
|
CWE-119 CWE-843
Incorrect Access of Indexable Resource ('Range Error') Type Confusion
|
CVE-2020-10757
|
2024-11-21 13:56 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210444
|
4.3 |
MEDIUM
Network
|
gnome fedoraproject
|
networkmanager fedora
|
It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network us…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-10754
|
2024-11-21 13:56 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210445
|
8.6 |
HIGH
Network
|
perl fedoraproject opensuse netapp oracle
|
perl fedora leap snap_creator_framework oncommand_workflow_automation communications_eagle_lnp_application_processor sd-wan_aware enterprise_manager_base_platform communicatio…
|
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of in…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-10878
|
2024-11-21 13:56 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210446
|
9.8 |
CRITICAL
Network
|
octobercms
|
debugbar
|
The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all information pertaining to each request including session data) whenever it is enabled. …
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-11094
|
2024-11-21 13:56 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210447
|
5.8 |
MEDIUM
Network
|
weave
|
weave_net
|
In Weave Net before version 2.6.3, an attacker able to run a process as root in a container is able to respond to DNS requests from the host and thereby insert themselves as a fake service. In a clus…
|
-
|
CVE-2020-11091
|
2024-11-21 13:56 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210448
|
7.5 |
HIGH
Network
|
nghttp2 debian opensuse fedoraproject oracle nodejs
|
nghttp2 debian_linux leap fedora enterprise_communications_broker graalvm mysql blockchain_platform banking_extensibility_workbench node.js
|
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a…
|
-
|
CVE-2020-11080
|
2024-11-21 13:56 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210449
|
6.1 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and external redirection via HTML content in a MediaWiki page.
|
CWE-601
Open Redirect
|
CVE-2020-10959
|
2024-11-21 13:56 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210450
|
5.5 |
MEDIUM
Network
|
freerdp opensuse debian
|
freerdp leap debian_linux
|
In FreeRDP before 2.1.0, there is an out-of-bound read in irp functions (parallel_process_irp_create, serial_process_irp_create, drive_process_irp_write, printer_process_irp_write, rdpei_recv_pdu, se…
|
-
|
CVE-2020-11089
|
2024-11-21 13:56 |
2020-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|