|
211201
|
6.1 |
MEDIUM
Network
|
siemens
|
sicam_mmu_firmware sicam_sgu_firmware sicam_t_firmware
|
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). The web server could allow Cross-Site Scripting (XSS) attacks if uns…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10043
|
2024-11-21 13:54 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211202
|
9.8 |
CRITICAL
Network
|
siemens
|
sicam_mmu_firmware sicam_sgu_firmware sicam_t_firmware
|
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). A buffer overflow in various positions of the web application might …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-10042
|
2024-11-21 13:54 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211203
|
6.1 |
MEDIUM
Network
|
siemens
|
sicam_mmu_firmware sicam_sgu_firmware sicam_t_firmware
|
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). A stored Cross-Site-Scripting (XSS) vulnerability is present in diff…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10041
|
2024-11-21 13:54 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211204
|
5.5 |
MEDIUM
Local
|
siemens
|
sicam_mmu_firmware sicam_sgu_firmware sicam_t_firmware
|
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with local access to the device might be able to retriev…
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2020-10040
|
2024-11-21 13:54 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211205
|
8.1 |
HIGH
Network
|
siemens
|
sicam_mmu_firmware sicam_sgu_firmware sicam_t_firmware
|
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker in a privileged network position between a legitimate us…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-10039
|
2024-11-21 13:54 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211206
|
9.8 |
CRITICAL
Network
|
siemens
|
sicam_mmu_firmware sicam_sgu_firmware sicam_t_firmware
|
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with access to the device's web server might be able to …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-10038
|
2024-11-21 13:54 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211207
|
7.5 |
HIGH
Network
|
siemens
|
sicam_mmu_firmware sicam_sgu_firmware sicam_t_firmware
|
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). By performing a flooding attack against the web server, an attacker …
|
CWE-125
Out-of-bounds Read
|
CVE-2020-10037
|
2024-11-21 13:54 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211208
|
5.5 |
MEDIUM
Local
|
python debian fedoraproject canonical
|
pillow debian_linux fedora ubuntu_linux
|
Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-10177
|
2024-11-21 13:54 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211209
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_rt_8.1 windows_server_2019
|
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique fro…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0986
|
2024-11-21 13:54 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211210
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_rt_8.1 windows_server_2019
|
An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, aka 'Windows GDI Elevation of Privilege Vulnerability'. This CVE …
|
NVD-CWE-noinfo
|
CVE-2020-0916
|
2024-11-21 13:54 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|