|
210611
|
9.1 |
CRITICAL
Network
|
treck
|
tcp\/ip
|
The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might allow remote attackers to trigger an information leak.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-11898
|
2024-11-21 13:58 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210612
|
10.0 |
CRITICAL
Network
|
treck
|
tcp\/ip
|
The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-11897
|
2024-11-21 13:58 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210613
|
10.0 |
CRITICAL
Network
|
treck
|
tcp\/ip
|
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.
|
CWE-119 CWE-787
Incorrect Access of Indexable Resource ('Range Error') Out-of-bounds Write
|
CVE-2020-11896
|
2024-11-21 13:58 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210614
|
4.3 |
MEDIUM
Network
|
microfocus
|
arcsight_management_center
|
Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotel…
|
NVD-CWE-noinfo
|
CVE-2020-11841
|
2024-11-21 13:58 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210615
|
4.3 |
MEDIUM
Network
|
microfocus
|
arcsight_management_center
|
Unauthorized information disclosure vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotel…
|
NVD-CWE-noinfo
|
CVE-2020-11840
|
2024-11-21 13:58 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210616
|
5.4 |
MEDIUM
Network
|
microfocus
|
arcsight_management_center
|
Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Management Center product, Affecting versions 2.6.1, 2.7.x, 2.8.x, 2.9.x prior to 2.9.4. The vulnerabilities could be remotely exploit…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11838
|
2024-11-21 13:58 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210617
|
6.1 |
MEDIUM
Network
|
microfocus
|
arcsight_logger
|
Cross Site Scripting (XSS) vulnerability in Micro Focus ArcSight Logger product, affecting all version from 6.6.1 up to version 7.0.1. The vulnerabilities could be remotely exploited resulting in Cro…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11839
|
2024-11-21 13:58 |
2020-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210618
|
8.1 |
HIGH
Network
|
mids\'_reborn_hero_designer_project
|
mids\'_reborn_hero_designer
|
Mids' Reborn Hero Designer 2.6.0.7 downloads the update manifest, as well as update files, over cleartext HTTP. Additionally, the application does not perform file integrity validation for files afte…
|
CWE-345 CWE-319
Insufficient Verification of Data Authenticity Cleartext Transmission of Sensitive Information
|
CVE-2020-11614
|
2024-11-21 13:58 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210619
|
7.8 |
HIGH
Local
|
mids\'_reborn_hero_designer_project
|
mids\'_reborn_hero_designer
|
Mids' Reborn Hero Designer 2.6.0.7 has an elevation of privilege vulnerability due to default and insecure permissions being set for the installation folder. By default, the Authenticated Users group…
|
CWE-427 CWE-732
Uncontrolled Search Path Element Incorrect Permission Assignment for Critical Resource
|
CVE-2020-11613
|
2024-11-21 13:58 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210620
|
7.5 |
HIGH
Network
|
arista
|
veos cloudeos
|
A vulnerability exists in Arista’s Cloud EOS VM / vEOS 4.23.2M and below releases in the 4.23.x train, 4.22.4M and below releases in the 4.22.x train, 4.21.3M to 4.21.9M releases in the 4.21.x train,…
|
NVD-CWE-noinfo
|
CVE-2020-11622
|
2024-11-21 13:58 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|