|
197401
|
7.5 |
HIGH
Network
|
rockwellautomation
|
factorytalk_diagnostics
|
An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics event log. The attacker can specify long fields in the log en…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-5807
|
2024-11-21 14:34 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197402
|
5.5 |
MEDIUM
Local
|
rockwellautomation
|
factorytalk_linx
|
An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-5806
|
2024-11-21 14:34 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197403
|
7.5 |
HIGH
Network
|
rockwellautomation
|
factorytalk_linx
|
An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandle…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-5802
|
2024-11-21 14:34 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197404
|
7.5 |
HIGH
Network
|
rockwellautomation
|
factorytalk_linx
|
An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::HandleRequest function in RnaDaSvr.dll, resulting in p…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-5801
|
2024-11-21 14:34 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197405
|
4.8 |
MEDIUM
Network
|
nec
|
ism_server
|
iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not verify a server certificate properly, which allows a man-in-the-middle attacker to …
|
CWE-295
Improper Certificate Validation
|
CVE-2020-5684
|
2024-11-21 14:34 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197406
|
7.8 |
HIGH
Local
|
epson
|
offirio_synergyware_printdirector epsonnet_setupmanager
|
Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio SynergyWare PrintDirector versions 1.6x/1.6y and earlier allows …
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-5681
|
2024-11-21 14:34 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197407
|
7.5 |
HIGH
Network
|
tenable
|
tenable.sc
|
In certain scenarios in Tenable.sc prior to 5.17.0, a scanner could potentially be used outside the user's defined scan zone without a particular zone being specified within the Automatic Distributio…
|
NVD-CWE-noinfo
|
CVE-2020-5808
|
2024-11-21 14:34 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197408
|
8.1 |
HIGH
Network
|
marvell
|
qconvergeconsole
|
Relative Path Traversal in Marvell QConvergeConsole GUI 5.5.0.74 allows a remote, authenticated attacker to delete arbitrary files on disk as SYSTEM or root.
|
CWE-22
Path Traversal
|
CVE-2020-5803
|
2024-11-21 14:34 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197409
|
7.5 |
HIGH
Network
|
weseek
|
growi
|
Directory traversal vulnerability in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier GROWI versions prior to v4.2.3 (v4.2 …
|
CWE-22
Path Traversal
|
CVE-2020-5683
|
2024-11-21 14:34 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197410
|
7.5 |
HIGH
Network
|
weseek
|
growi
|
Improper input validation in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier GROWI versions prior to v4.2.3 (v4.2 Series),…
|
CWE-20 CWE-400
Improper Input Validation Uncontrolled Resource Consumption
|
CVE-2020-5682
|
2024-11-21 14:34 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|