|
211101
|
9.8 |
CRITICAL
Network
|
qualcomm
|
msm8960 mdm9607 mdm9650 msm8909w mdm9635m mdm9655 mdm9615 mdm9625 mdm9640 mdm9645 sdm630 qca6174a qca6574au qca6584au qca9379 msm8976 msm8952 apq809…
|
Integer multiplication overflow resulting in lower buffer size allocation than expected causes memory access out of bounds resulting in possible device instability in Snapdragon Auto, Snapdragon Comp…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-11137
|
2024-11-21 13:56 |
2021-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211102
|
9.8 |
CRITICAL
Network
|
qualcomm
|
msm8960 mdm9206 mdm9607 mdm9650 msm8909w mdm9635m mdm9655 mdm9615 mdm9625 mdm9640 mdm9645 qca9379 msm8976 sdm630 qca6584au qca6584 qca6574au qca6174…
|
Buffer Over-read in audio driver while using malloc management function due to not returning NULL for zero sized memory requirement in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sn…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-11136
|
2024-11-21 13:56 |
2021-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211103
|
9.8 |
CRITICAL
Network
|
webswing
|
webswing
|
JsLink in Webswing before 2.6.12 LTS, and 2.7.x and 20.x before 20.1, allows remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-11103
|
2024-11-21 13:56 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211104
|
7.5 |
HIGH
Network
|
linuxfoundation
|
indy-node
|
Hyperledger Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In Hyperledger Indy before version 1.12.4, there is lack of signature verification on a s…
|
-
|
CVE-2020-11093
|
2024-11-21 13:56 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211105
|
5.3 |
MEDIUM
Network
|
redhat
|
keycloak
|
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this param…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-10770
|
2024-11-21 13:56 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211106
|
7.5 |
HIGH
Network
|
nlnetlabs
|
unbound
|
An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query int…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-10772
|
2024-11-21 13:56 |
2020-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211107
|
5.5 |
MEDIUM
Local
|
heketi_project redhat
|
heketi enterprise_linux gluster_storage openshift_container_platform
|
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive …
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-10763
|
2024-11-21 13:56 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211108
|
5.5 |
MEDIUM
Local
|
redhat
|
gluster-block
|
An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes recording passwords to the cmd_history.log file wh…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-10762
|
2024-11-21 13:56 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211109
|
4.8 |
MEDIUM
Network
|
redhat
|
keycloak
|
A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10776
|
2024-11-21 13:56 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211110
|
7.1 |
HIGH
Local
|
qualcomm
|
apq8009_firmware apq8096au_firmware apq8098_firmware mdm8207_firmware mdm9150_firmware mdm9205_firmware mdm9206_firmware mdm9207_firmware mdm9250_firmware mdm9607_firmware<…
|
u'Buffer over read in boot due to size check ignored before copying GUID attribute from request to response' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-11132
|
2024-11-21 13:56 |
2020-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|