|
210451
|
9.8 |
CRITICAL
Network
|
libgit2 debian
|
libgit2 debian_linux
|
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2020-12278
|
2024-11-21 13:59 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210452
|
7.5 |
HIGH
Network
|
wavlink
|
wl-wn579g3_firmware wl-wn575a3_firmware wl-wn530hg4_firmware wn531g3_firmware wn533a8_firmware wn531a6_firmware wn551k1_firmware wn535g3_firmware wn530h4_firmware wn57x93_f…
|
An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage. The devices automatically…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-12266
|
2024-11-21 13:59 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210453
|
7.8 |
HIGH
Local
|
valvesoftware
|
source
|
Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a different user account.
|
CWE-78
OS Command
|
CVE-2020-12242
|
2024-11-21 13:59 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210454
|
8.8 |
HIGH
Network
|
amd
|
atillk64
|
AMD ATI atillk64.sys 5.11.9.0 allows low-privileged users to interact directly with physical memory by calling one of several driver routines that map physical memory into the virtual address space o…
|
CWE-862
Missing Authorization
|
CVE-2020-12138
|
2024-11-21 13:59 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210455
|
9.8 |
CRITICAL
Network
|
farukawa
|
electric_consciousmap
|
The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java deserialization.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-12133
|
2024-11-21 13:59 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210456
|
7.5 |
HIGH
Network
|
prestashop
|
correos_express
|
The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such as a service's owner password that can be used to modify orders via SOAP. Attack…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-12120
|
2024-11-21 13:59 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210457
|
5.3 |
MEDIUM
Network
|
trusteddomain fedoraproject
|
opendmarc fedora
|
OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsin…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2020-12272
|
2024-11-21 13:59 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210458
|
9.8 |
CRITICAL
Network
|
testlink
|
testlink
|
In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is not constrained to lib/cfields/cfieldsView.php at the web s…
|
NVD-CWE-noinfo
|
CVE-2020-12274
|
2024-11-21 13:59 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210459
|
7.5 |
HIGH
Network
|
testlink
|
testlink
|
In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.
|
CWE-311 CWE-522
Missing Encryption of Sensitive Data Insufficiently Protected Credentials
|
CVE-2020-12273
|
2024-11-21 13:59 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210460
|
6.1 |
MEDIUM
Network
|
grafana
|
grafana
|
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12052
|
2024-11-21 13:59 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|