|
210291
|
7.8 |
HIGH
Local
|
idrive
|
idrive
|
IDrive before 6.7.3.19 on Windows installs by default to %PROGRAMFILES(X86)%\IDriveWindows with weak folder permissions granting any user modify permission (i.e., NT AUTHORITY\Authenticated Users:(OI…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-15351
|
2024-11-21 14:05 |
2020-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210292
|
7.5 |
HIGH
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /cnr requests.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-15336
|
2024-11-21 14:05 |
2020-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210293
|
7.5 |
HIGH
Network
|
zyxel
|
cloudcnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /registerCpe requests.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-15335
|
2024-11-21 14:05 |
2020-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210294
|
9.8 |
CRITICAL
Network
|
zyxel
|
cloud_cnm_secumanager
|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= for eval injection of Python code.
|
CWE-94
Code Injection
|
CVE-2020-15348
|
2024-11-21 14:05 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210295
|
7.2 |
HIGH
Network
|
turnkeylinux
|
support_incident_tracker
|
Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2 allows post-authentication SQL injection via the site_edit.php typeid or site parameter, the search_incidents_advanced.php search_title parame…
|
CWE-89
SQL Injection
|
CVE-2020-15308
|
2024-11-21 14:05 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210296
|
5.5 |
MEDIUM
Local
|
openexr fedoraproject opensuse debian canonical
|
openexr fedora leap debian_linux ubuntu_linux
|
An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-15306
|
2024-11-21 14:05 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210297
|
5.5 |
MEDIUM
Local
|
openexr fedoraproject opensuse debian canonical
|
openexr fedora leap debian_linux ubuntu_linux
|
An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp.
|
CWE-416
Use After Free
|
CVE-2020-15305
|
2024-11-21 14:05 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210298
|
5.5 |
MEDIUM
Local
|
openexr fedoraproject opensuse
|
openexr fedora leap
|
An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by …
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-15304
|
2024-11-21 14:05 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210299
|
7.5 |
HIGH
Network
|
argent
|
recoverymanager
|
In Argent RecoveryManager before 0xdc350d09f71c48c5D22fBE2741e4d6A03970E192, the executeRecovery function does not require any signatures in the zero-guardian case, which allows attackers to cause a …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-15302
|
2024-11-21 14:05 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210300
|
7.5 |
HIGH
Network
|
acronis
|
agent
|
A logic bug in system monitoring driver of Acronis Agent after 12.5.21540 and before 12.5.23094 allowed to bypass Windows memory protection and access sensitive data.
|
NVD-CWE-noinfo
|
CVE-2020-14999
|
2024-11-21 14:04 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|