|
211191
|
5.4 |
MEDIUM
Network
|
freerdp fedoraproject opensuse canonical debian
|
freerdp fedora leap ubuntu_linux debian_linux
|
In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is…
|
-
|
CVE-2020-11095
|
2024-11-21 13:56 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211192
|
6.5 |
MEDIUM
Local
|
redhat
|
ansible_tower
|
An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable and exposed from the rsyslog configuration file, w…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-10782
|
2024-11-21 13:56 |
2020-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211193
|
7.5 |
HIGH
Network
|
linuxfoundation
|
indy-node
|
In Indy Node 1.12.2, there is an Uncontrolled Resource Consumption vulnerability. Indy Node has a bug in TAA handling code. The current primary can be crashed with a malformed transaction from a clie…
|
-
|
CVE-2020-11090
|
2024-11-21 13:56 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211194
|
6.5 |
MEDIUM
Network
|
redhat canonical
|
openstack-cinder ubuntu_linux
|
An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before openstack-cinder 15.2.0 and all openstack-cinder 16…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-10755
|
2024-11-21 13:56 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211195
|
5.0 |
MEDIUM
Network
|
qemu redhat opensuse canonical
|
qemu enterprise_linux leap ubuntu_linux
|
An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near th…
|
CWE-617
Reachable Assertion
|
CVE-2020-10761
|
2024-11-21 13:56 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211196
|
7.8 |
HIGH
Local
|
linux opensuse redhat fedoraproject debian canonical netapp
|
linux_kernel leap enterprise_linux enterprise_mrg fedora debian_linux ubuntu_linux cloud_backup steelstore_cloud_integrated_storage active_iq_unified_manager
|
A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privi…
|
CWE-119 CWE-843
Incorrect Access of Indexable Resource ('Range Error') Type Confusion
|
CVE-2020-10757
|
2024-11-21 13:56 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211197
|
4.3 |
MEDIUM
Network
|
gnome fedoraproject
|
networkmanager fedora
|
It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network us…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-10754
|
2024-11-21 13:56 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211198
|
8.6 |
HIGH
Network
|
perl fedoraproject opensuse netapp oracle
|
perl fedora leap snap_creator_framework oncommand_workflow_automation communications_eagle_lnp_application_processor sd-wan_aware enterprise_manager_base_platform communicatio…
|
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of in…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-10878
|
2024-11-21 13:56 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211199
|
9.8 |
CRITICAL
Network
|
octobercms
|
debugbar
|
The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all information pertaining to each request including session data) whenever it is enabled. …
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-11094
|
2024-11-21 13:56 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211200
|
5.8 |
MEDIUM
Network
|
weave
|
weave_net
|
In Weave Net before version 2.6.3, an attacker able to run a process as root in a container is able to respond to DNS requests from the host and thereby insert themselves as a fake service. In a clus…
|
-
|
CVE-2020-11091
|
2024-11-21 13:56 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|