|
210771
|
7.8 |
HIGH
Local
|
mozilla
|
firefox firefox_esr thunderbird
|
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted …
|
CWE-78
OS Command
|
CVE-2020-12393
|
2024-11-21 13:59 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210772
|
4.3 |
MEDIUM
Network
|
mozilla canonical
|
thunderbird ubuntu_linux
|
By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0.
|
CWE-346
Origin Validation Error
|
CVE-2020-12397
|
2024-11-21 13:59 |
2020-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210773
|
6.6 |
MEDIUM
Local
|
splashtop
|
software_updater streamer
|
A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and named pipe allow for local privilege escalation to NT…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-12431
|
2024-11-21 13:59 |
2020-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210774
|
8.8 |
HIGH
Local
|
unisys
|
algol_compiler
|
Unisys ALGOL Compiler 58.1 before 58.1a.15, 59.1 before 59.1a.9, and 60.0 before 60.0a.5 can emit invalid code sequences under rare circumstances related to syntax. The resulting code could, for exam…
|
NVD-CWE-Other
|
CVE-2020-12647
|
2024-11-21 13:59 |
2020-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210775
|
8.2 |
HIGH
Adjacent
|
rockwellautomation
|
eds_subsystem rsnetworx rslinx rslinx_enterprise studio_5000_logix_designer
|
Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterprise): Versions 6.00, 6.10, and 6.11, RSLinx Classic: Version 4.11.00 and prior, R…
|
CWE-89
SQL Injection
|
CVE-2020-12034
|
2024-11-21 13:59 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210776
|
5.5 |
MEDIUM
Local
|
rockwellautomation
|
eds_subsystem rsnetworx rslinx rslinx_enterprise studio_5000_logix_designer
|
Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterprise): Versions 6.00, 6.10, and 6.11, RSLinx Classic: Version 4.11.00 and prior, R…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12038
|
2024-11-21 13:59 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210777
|
7.5 |
HIGH
Network
|
powerdns fedoraproject debian opensuse
|
recursor fedora debian_linux leap backports_sle
|
An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated in SyncRes::processAnswer, allow…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-12244
|
2024-11-21 13:59 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210778
|
5.4 |
MEDIUM
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbitrary JavaScript in the deviceId GET parameter to …
|
CWE-79
Cross-site Scripting
|
CVE-2020-12256
|
2024-11-21 13:59 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210779
|
8.8 |
HIGH
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality. vendor.crud.php accepts a file upload by checking content-type without considering th…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12255
|
2024-11-21 13:59 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210780
|
9.1 |
CRITICAL
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application can reuse a session via PHPSESSID. Also, an attacker can exploit this vulnerab…
|
CWE-384
Session Fixation
|
CVE-2020-12258
|
2024-11-21 13:59 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|