|
211131
|
7.5 |
HIGH
Network
|
redhat
|
openshift_container_platform
|
A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with th…
|
CWE-532 CWE-522
Inclusion of Sensitive Information in Log Files Insufficiently Protected Credentials
|
CVE-2020-10752
|
2024-11-21 13:55 |
2020-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211132
|
4.4 |
MEDIUM
Local
|
linux opensuse canonical netapp
|
linux_kernel leap ubuntu_linux steelstore_cloud_integrated_storage active_iq_unified_manager solidfire hci_management_node aff_a700_firmware h410c_firmware h300s_firmware
|
A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data.
|
-
|
CVE-2020-10732
|
2024-11-21 13:55 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211133
|
7.5 |
HIGH
Network
|
redhat netapp
|
undertow oncommand_insight jboss_enterprise_application_platform openshift_application_runtimes
|
A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-10705
|
2024-11-21 13:55 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211134
|
7.5 |
HIGH
Network
|
inductiveautomation
|
ignition_gateway
|
The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-10644
|
2024-11-21 13:55 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211135
|
8.2 |
HIGH
Network
|
perl fedoraproject opensuse oracle
|
perl fedora leap communications_eagle_lnp_application_processor sd-wan_edge enterprise_manager_base_platform communications_billing_and_revenue_management communications_offline_…
|
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2020-10543
|
2024-11-21 13:55 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211136
|
5.5 |
MEDIUM
Local
|
qemu
|
qemu
|
A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generatio…
|
NVD-CWE-Other
|
CVE-2020-10702
|
2024-11-21 13:55 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211137
|
9.8 |
CRITICAL
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, gr…
|
CWE-89
SQL Injection
|
CVE-2020-10549
|
2024-11-21 13:55 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211138
|
9.8 |
CRITICAL
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, gra…
|
CWE-89
SQL Injection
|
CVE-2020-10548
|
2024-11-21 13:55 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211139
|
9.8 |
CRITICAL
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to late…
|
CWE-89
SQL Injection
|
CVE-2020-10547
|
2024-11-21 13:55 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211140
|
9.8 |
CRITICAL
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral mo…
|
CWE-89
SQL Injection
|
CVE-2020-10546
|
2024-11-21 13:55 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|