|
196951
|
5.5 |
MEDIUM
Local
|
blackberry
|
unified_endpoint_manager
|
An improper input validation vulnerability in the UEM Core of BlackBerry UEM version(s) 12.13.0, 12.12.1a QF2 (and earlier), and 12.11.1 QF3 (and earlier) could allow an attacker to potentially cause…
|
CWE-20
Improper Input Validation
|
CVE-2020-6933
|
2024-11-21 14:36 |
2020-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196952
|
9.8 |
CRITICAL
Network
|
zte
|
zxone_19700_snpe_firmware
|
A ZTE product is impacted by the improper access control vulnerability. Due to lack of an authentication protection mechanism in the program, attackers could use this vulnerability to gain access rig…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-6875
|
2024-11-21 14:36 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196953
|
5.3 |
MEDIUM
Network
|
php fedoraproject debian opensuse canonical netapp tenable
|
php fedora debian_linux leap ubuntu_linux clustered_data_ontap tenable.sc
|
In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with pref…
|
CWE-565
Reliance on Cookies without Validation and Integrity Checking
|
CVE-2020-7070
|
2024-11-21 14:36 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196954
|
6.5 |
MEDIUM
Network
|
php fedoraproject debian opensuse canonical netapp oracle tenable
|
php fedora debian_linux leap ubuntu_linux clustered_data_ontap communications_diameter_signaling_router tenable.sc
|
In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually use…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-7069
|
2024-11-21 14:36 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196955
|
7.8 |
HIGH
Local
|
eaton
|
9000x_programming_and_configuration_software
|
A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code by replacing the required DLLs with malicious DLL…
|
CWE-427 CWE-426
Uncontrolled Search Path Element Untrusted Search Path
|
CVE-2020-6654
|
2024-11-21 14:36 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196956
|
7.5 |
HIGH
Network
|
arubanetworks
|
cx_6200f_firmware cx_6300_firmware cx_6400_firmware cx_8320_firmware cx_8325_firmware cx_8400_firmware
|
Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local D…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7122
|
2024-11-21 14:36 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196957
|
7.5 |
HIGH
Network
|
arubanetworks
|
cx_6200f_firmware cx_6300_firmware cx_6400_firmware cx_8320_firmware cx_8325_firmware cx_8400_firmware
|
Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local D…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7121
|
2024-11-21 14:36 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196958
|
7.4 |
HIGH
Network
|
bosch
|
smart_home
|
Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17.1 potentially allows to intercept video contents by performing a man-in-the-mi…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-6781
|
2024-11-21 14:36 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196959
|
4.3 |
MEDIUM
Network
|
mcafee
|
email_gateway
|
Path Traversal vulnerability in McAfee McAfee Email Gateway (MEG) prior to 7.6.406 allows remote attackers to traverse the file system to access files or directories that are outside of the restricte…
|
CWE-22
Path Traversal
|
CVE-2020-7268
|
2024-11-21 14:36 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196960
|
3.6 |
LOW
Local
|
php debian tenable
|
php debian_linux tenable.sc
|
In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which …
|
CWE-416
Use After Free
|
CVE-2020-7068
|
2024-11-21 14:36 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|