|
211421
|
5.3 |
MEDIUM
Network
|
meinbwa
|
direx-pro_firmware
|
BWA DiREX-Pro 1.2181 devices allow full path disclosure via an invalid name array parameter to val_soft.php3.
|
NVD-CWE-noinfo
|
CVE-2020-10249
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211422
|
7.5 |
HIGH
Network
|
meinbwa
|
direx-pro_firmware
|
BWA DiREX-Pro 1.2181 devices allow remote attackers to discover passwords via a direct request to val_users.php3.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2020-10248
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211423
|
6.1 |
MEDIUM
Network
|
misp
|
misp
|
MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is related to app/View/Elements/Events/View/sighting_field.ctp.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10247
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211424
|
6.1 |
MEDIUM
Network
|
misp
|
misp
|
MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10246
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211425
|
7.5 |
HIGH
Network
|
jpaseto_project
|
jpaseto
|
JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-10244
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211426
|
5.5 |
MEDIUM
Local
|
froxlor
|
froxlor
|
An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords into files in /tmp, setting proper permissions only after writing the sensitive da…
|
CWE-362
Race Condition
|
CVE-2020-10237
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211427
|
6.1 |
MEDIUM
Local
|
froxlor
|
froxlor
|
An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the installation directory was not writable. This allowed local attackers to cause…
|
CWE-20
Improper Input Validation
|
CVE-2020-10236
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211428
|
8.8 |
HIGH
Network
|
froxlor
|
froxlor
|
An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via the database configuration options that were passed …
|
CWE-78 CWE-116
OS Command Improper Encoding or Escaping of Output
|
CVE-2020-10235
|
2024-11-21 13:55 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211429
|
9.1 |
CRITICAL
Network
|
sleuthkit
|
the_sleuth_kit
|
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfs_dinode_lookup in fs/ntfs.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-10233
|
2024-11-21 13:55 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211430
|
9.8 |
CRITICAL
Network
|
sleuthkit debian fedoraproject
|
the_sleuth_kit debian_linux fedora
|
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10232
|
2024-11-21 13:55 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|