|
210561
|
7.5 |
HIGH
Network
|
fastecdsa_project
|
fastecdsa
|
An issue was discovered in fastecdsa before 2.1.2. When using the NIST P-256 curve in the ECDSA implementation, the point at infinity is mishandled. This means that for an extreme value in k and s^-1…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-12607
|
2024-11-21 13:59 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210562
|
9.8 |
CRITICAL
Network
|
ge
|
rt430_firmware rt431_firmware rt434_firmware
|
GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05. The device’s vulnerability in the web application could allow multiple unauthenticated attacks that …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-12017
|
2024-11-21 13:59 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210563
|
7.5 |
HIGH
Network
|
openbsd
|
openssh
|
The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, which allows a malicious unprivileged user on the remote server to overwrite arbit…
|
CWE-20
Improper Input Validation
|
CVE-2020-12062
|
2024-11-21 13:59 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210564
|
10.0 |
CRITICAL
Network
|
swarco
|
cpu_ls4000_firmware
|
An open port used for debugging in SWARCOs CPU LS4000 Series with versions starting with G4... grants root access to the device without access control via network. A malicious user could use this vul…
|
NVD-CWE-Other
|
CVE-2020-12493
|
2024-11-21 13:59 |
2020-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210565
|
5.5 |
MEDIUM
Local
|
mozilla canonical
|
thunderbird firefox firefox_esr ubuntu_linux
|
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and past…
|
CWE-22
Path Traversal
|
CVE-2020-12392
|
2024-11-21 13:59 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210566
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scripts that should have been blocked, albeit with a unique opa…
|
CWE-863
Incorrect Authorization
|
CVE-2020-12391
|
2024-11-21 13:59 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210567
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-12390
|
2024-11-21 13:59 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210568
|
10.0 |
CRITICAL
Network
|
mozilla
|
firefox firefox_esr
|
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerab…
|
CWE-20
Improper Input Validation
|
CVE-2020-12389
|
2024-11-21 13:59 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210569
|
10.0 |
CRITICAL
Network
|
mozilla
|
firefox firefox_esr
|
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerab…
|
CWE-20
Improper Input Validation
|
CVE-2020-12388
|
2024-11-21 13:59 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210570
|
8.1 |
HIGH
Network
|
mozilla
|
thunderbird firefox firefox_esr
|
A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Fire…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2020-12387
|
2024-11-21 13:59 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|