|
197521
|
6.5 |
MEDIUM
Network
|
php fedoraproject debian opensuse canonical netapp oracle tenable
|
php fedora debian_linux leap ubuntu_linux clustered_data_ontap communications_diameter_signaling_router tenable.sc
|
In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually use…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-7069
|
2024-11-21 14:36 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197522
|
7.8 |
HIGH
Local
|
eaton
|
9000x_programming_and_configuration_software
|
A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code by replacing the required DLLs with malicious DLL…
|
CWE-427 CWE-426
Uncontrolled Search Path Element Untrusted Search Path
|
CVE-2020-6654
|
2024-11-21 14:36 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197523
|
7.5 |
HIGH
Network
|
arubanetworks
|
cx_6200f_firmware cx_6300_firmware cx_6400_firmware cx_8320_firmware cx_8325_firmware cx_8400_firmware
|
Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local D…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7122
|
2024-11-21 14:36 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197524
|
7.5 |
HIGH
Network
|
arubanetworks
|
cx_6200f_firmware cx_6300_firmware cx_6400_firmware cx_8320_firmware cx_8325_firmware cx_8400_firmware
|
Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local D…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7121
|
2024-11-21 14:36 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197525
|
7.4 |
HIGH
Network
|
bosch
|
smart_home
|
Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17.1 potentially allows to intercept video contents by performing a man-in-the-mi…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-6781
|
2024-11-21 14:36 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197526
|
4.3 |
MEDIUM
Network
|
mcafee
|
email_gateway
|
Path Traversal vulnerability in McAfee McAfee Email Gateway (MEG) prior to 7.6.406 allows remote attackers to traverse the file system to access files or directories that are outside of the restricte…
|
CWE-22
Path Traversal
|
CVE-2020-7268
|
2024-11-21 14:36 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197527
|
3.6 |
LOW
Local
|
php debian tenable
|
php debian_linux tenable.sc
|
In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which …
|
CWE-416
Use After Free
|
CVE-2020-7068
|
2024-11-21 14:36 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197528
|
4.9 |
MEDIUM
Network
|
arubanetworks
|
analytics_and_location_engine
|
A vulnerability exists in the Aruba Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier firmware that allows an already authenticated administrative user to arbitrarily m…
|
NVD-CWE-noinfo
|
CVE-2020-7119
|
2024-11-21 14:36 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197529
|
9.1 |
CRITICAL
Network
|
zte
|
zxiptv_firmware
|
A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use this vulnerability for account credential enumeration…
|
CWE-327 CWE-522
Use of a Broken or Risky Cryptographic Algorithm Insufficiently Protected Credentials
|
CVE-2020-6874
|
2024-11-21 14:36 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197530
|
5.3 |
MEDIUM
Network
|
zte
|
zxr10_2800-4_almpufb\(low\)_firmware
|
A ZTE product has a DoS vulnerability. Because the equipment couldn’t distinguish the attack packets and normal packets with valid http links, the remote attackers could use this vulnerability to cau…
|
NVD-CWE-noinfo
|
CVE-2020-6873
|
2024-11-21 14:36 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|