|
197341
|
10.0 |
CRITICAL
Network
|
sap
|
introscope_enterprise_manager
|
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentia…
|
CWE-78
OS Command
|
CVE-2020-6364
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197342
|
4.6 |
MEDIUM
Network
|
sap
|
commerce_cloud
|
SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a user. These sessions are established after the user has authenticated with userna…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-6363
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197343
|
6.1 |
MEDIUM
Network
|
sap
|
netweaver_enterprise_portal
|
SAP NetWeaver Enterprise Portal (Fiori Framework Page) versions - 7.50, 7.31, 7.40, does not sufficiently encode user-controlled inputs and allows an attacker on a valid session to create an XSS that…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6323
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197344
|
6.1 |
MEDIUM
Network
|
sap
|
netweaver_application_server_java
|
SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allows an unauthenticated attacker to include JavaScript blocks in any web page or URL with different sy…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6319
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197345
|
5.4 |
MEDIUM
Network
|
sap
|
commerce_cloud
|
SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several we…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6272
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197346
|
7.5 |
HIGH
Network
|
rockwellautomation
|
allen-bradley_flex_io_1794-aent\/b_firmware
|
An exploitable denial of service vulnerability exists in the ENIP Request Path Port Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A specially crafted network request can cause a loss of…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-6083
|
2024-11-21 14:35 |
2020-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197347
|
7.5 |
HIGH
Network
|
rockwellautomation
|
flex_i\/o_1794-aent\/b_firmware
|
An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A specially crafted network request can cause a loss of…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-6087
|
2024-11-21 14:35 |
2020-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197348
|
7.5 |
HIGH
Network
|
rockwellautomation
|
flex_i\/o_1794-aent\/b_firmware
|
An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A specially crafted network request can cause a loss of…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-6086
|
2024-11-21 14:35 |
2020-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197349
|
8.8 |
HIGH
Network
|
google debian opensuse fedoraproject
|
chrome debian_linux leap fedora backports_sle
|
Use after free in offscreen canvas in Google Chrome prior to 85.0.4183.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2020-6576
|
2024-11-21 14:35 |
2020-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197350
|
8.3 |
HIGH
Network
|
google debian opensuse fedoraproject
|
chrome debian_linux leap fedora backports_sle
|
Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
|
CWE-362
Race Condition
|
CVE-2020-6575
|
2024-11-21 14:35 |
2020-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|