|
211131
|
9.8 |
CRITICAL
Network
|
netkit_telnet_project fedoraproject debian arista oracle juniper
|
netkit_telnet fedora debian_linux eos communications_performance_intelligence_center junos
|
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-10188
|
2024-11-21 13:54 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211132
|
8.6 |
HIGH
Network
|
yubico
|
yubikey_one_time_password_validation_server
|
The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP v…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2020-10185
|
2024-11-21 13:54 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211133
|
7.5 |
HIGH
Network
|
yubico
|
yubikey_one_time_password_validation_server
|
The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remote attackers to cause a denial of service, aka SQL injection. NOTE: this issue …
|
CWE-89
SQL Injection
|
CVE-2020-10184
|
2024-11-21 13:54 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211134
|
9.8 |
CRITICAL
Network
|
eset
|
nod32_antivirus smart_security mobile_security smart_tv_security cyber_security
|
The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antiviru…
|
CWE-436
Interpretation Conflict
|
CVE-2020-10180
|
2024-11-21 13:54 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211135
|
7.0 |
HIGH
Local
|
timeshift_project fedoraproject canonical
|
timeshift fedora ubuntu_linux
|
init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the predictable location /tmp/timeshift. It follows symlinks in this location or uses…
|
CWE-362 CWE-59
Race Condition Link Following
|
CVE-2020-10174
|
2024-11-21 13:54 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211136
|
8.8 |
HIGH
Network
|
comtrend
|
vr-3033_firmware
|
Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metac…
|
CWE-78
OS Command
|
CVE-2020-10173
|
2024-11-21 13:54 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211137
|
5.4 |
MEDIUM
Network
|
phpgurukul
|
daily_expense_tracker_system
|
PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS, as demonstrated by the ExpenseItem or ExpenseCost parameter in manage-expense.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10107
|
2024-11-21 13:54 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211138
|
9.8 |
CRITICAL
Network
|
phpgurukul
|
daily_expense_tracker_system
|
PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to SQL injection, as demonstrated by the email parameter in index.php or register.php. The SQL injection allows to dump the MySQL database an…
|
CWE-89
SQL Injection
|
CVE-2020-10106
|
2024-11-21 13:54 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211139
|
5.3 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET request. Disclosure of source code allows for an at…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2020-10105
|
2024-11-21 13:54 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211140
|
4.3 |
MEDIUM
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad 3.0 through 3.2. After authentication, it transmits sensitive information to the user that may be compromised and used by an attacker to gain unauthorized access. Ha…
|
CWE-200
Information Exposure
|
CVE-2020-10104
|
2024-11-21 13:54 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|