|
210751
|
8.1 |
HIGH
Network
|
rockwellautomation
|
factorytalk_linx rslinx_classic
|
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version …
|
CWE-20
Improper Input Validation
|
CVE-2020-11999
|
2024-11-21 13:59 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210752
|
6.3 |
MEDIUM
Network
|
apache
|
karaf
|
In Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "admin" can actually invoke on an MBean. However there is a vulnerability there …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-11980
|
2024-11-21 13:59 |
2020-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210753
|
4.5 |
MEDIUM
Adjacent
|
philips
|
intellibridge_enterprise
|
Philips IntelliBridge Enterprise (IBE), Versions B.12 and prior, IntelliBridge Enterprise system integration with SureSigns (VS4), EarlyVue (VS30) and IntelliVue Guardian (IGS). Unencrypted user cred…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-12023
|
2024-11-21 13:59 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210754
|
7.5 |
HIGH
Network
|
inductiveautomation
|
ignition_gateway
|
The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14), allowing an attac…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-12004
|
2024-11-21 13:59 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210755
|
7.5 |
HIGH
Network
|
inductiveautomation
|
ignition_gateway
|
The affected product is vulnerable to the handling of serialized data. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted dat…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-12000
|
2024-11-21 13:59 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210756
|
5.5 |
MEDIUM
Local
|
freedesktop canonical
|
dbus ubuntu_linux
|
An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A loca…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2020-12049
|
2024-11-21 13:59 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210757
|
9.8 |
CRITICAL
Network
|
apache
|
unomi
|
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java proces…
|
NVD-CWE-noinfo
|
CVE-2020-11975
|
2024-11-21 13:59 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210758
|
7.5 |
HIGH
Network
|
fastecdsa_project
|
fastecdsa
|
An issue was discovered in fastecdsa before 2.1.2. When using the NIST P-256 curve in the ECDSA implementation, the point at infinity is mishandled. This means that for an extreme value in k and s^-1…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-12607
|
2024-11-21 13:59 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210759
|
9.8 |
CRITICAL
Network
|
ge
|
rt430_firmware rt431_firmware rt434_firmware
|
GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05. The device’s vulnerability in the web application could allow multiple unauthenticated attacks that …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-12017
|
2024-11-21 13:59 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210760
|
7.5 |
HIGH
Network
|
openbsd
|
openssh
|
The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, which allows a malicious unprivileged user on the remote server to overwrite arbit…
|
CWE-20
Improper Input Validation
|
CVE-2020-12062
|
2024-11-21 13:59 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|