|
210711
|
5.5 |
MEDIUM
Local
|
amd
|
radeon_software
|
Kernel Pool Address disclosure in AMD Graphics Driver for Windows 10 may lead to KASLR bypass.
|
NVD-CWE-noinfo
|
CVE-2020-12897
|
2024-11-21 14:00 |
2021-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210712
|
7.8 |
HIGH
Local
|
amd
|
radeon_software
|
Pool/Heap Overflow in AMD Graphics Driver for Windows 10 in Escape 0x110037 may lead to escalation of privilege, information disclosure or denial of service.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12895
|
2024-11-21 14:00 |
2021-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210713
|
7.8 |
HIGH
Local
|
amd
|
radeon_software
|
A potential privilege escalation/denial of service issue exists in the AMD Radeon Kernel Mode driver Escape 0x2000c00 Call handler. An attacker with low privilege could potentially induce a Windows B…
|
NVD-CWE-noinfo
|
CVE-2020-12964
|
2024-11-21 14:00 |
2021-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210714
|
5.4 |
MEDIUM
Network
|
fortinet
|
fortianalyzer
|
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiAnalyzer version 6.0.6 and below, version 6.4.4 allows attacker to execute unauthorized code or…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12814
|
2024-11-21 14:00 |
2021-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210715
|
7.5 |
HIGH
Network
|
3xlogic
|
infinias_eidc32_firmware
|
Missing TLS certificate validation on 3xLogic Infinias eIDC32 devices through 3.4.125 allows an attacker to intercept/control the channel by which door lock policies are applied.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-12681
|
2024-11-21 14:00 |
2021-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210716
|
8.1 |
HIGH
Adjacent
|
depstech
|
wifi_digital_microscope_3_firmware
|
DEPSTECH WiFi Digital Microscope 3 allows remote attackers to change the SSID and password, and demand a ransom payment from the rightful device owner, because there is no way to reset to Factory Def…
|
CWE-862
Missing Authorization
|
CVE-2020-12734
|
2024-11-21 14:00 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210717
|
7.5 |
HIGH
Network
|
depstech
|
wifi_digital_microscope_3_firmware
|
Certain Shenzhen PENGLIXIN components on DEPSTECH WiFi Digital Microscope 3, as used by Shekar Endoscope, allow a TELNET connection with the molinkadmin password for the molink account.
|
CWE-863
Incorrect Authorization
|
CVE-2020-12733
|
2024-11-21 14:00 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210718
|
6.5 |
MEDIUM
Adjacent
|
depstech
|
wifi_digital_microscope_3_firmware
|
DEPSTECH WiFi Digital Microscope 3 has a default SSID of Jetion_xxxxxxxx with a password of 12345678.
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2020-12732
|
2024-11-21 14:00 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210719
|
7.5 |
HIGH
Network
|
magicsmotion
|
flamingo_2_firmware
|
The MagicMotion Flamingo 2 application for Android stores data on an sdcard under com.vt.magicmotion/files/Pictures, whence it can be read by other applications.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-12731
|
2024-11-21 14:00 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210720
|
5.3 |
MEDIUM
Adjacent
|
magicsmotion
|
flamingo_2_firmware
|
MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-12730
|
2024-11-21 14:00 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|