|
198421
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
r00cpu_firmware r01cpu_firmware r02cpu_firmware r04cpu_firmware r08cpu_firmware r16cpu_firmware r32cpu_firmware r120cpu_firmware r08sfcpu_firmware r16sfcpu_firmware r32s…
|
Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series modules (R00/01/02CPU firmware version '19' and earlier, R04/08/16/32/120 (EN) CPU firmware version '51' and earlier, R08/16/32/1…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-5668
|
2024-11-21 14:34 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198422
|
4.3 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_advanced_web_application_firewall big-ip_analytics big-ip_application_acceleration_manager big-ip_application_secur…
|
In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able to obtain TCP sequence numbers from the BIG-IP system that can be reused in future connections with …
|
NVD-CWE-noinfo
|
CVE-2020-5947
|
2024-11-21 14:34 |
2020-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198423
|
9.8 |
CRITICAL
Network
|
valvesoftware
|
game_networking_sockets
|
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_ReceiveUnreliableSegment(), leading to a Heap-Based Buffer Underfl…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6016
|
2024-11-21 14:34 |
2020-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198424
|
9.8 |
CRITICAL
Network
|
riken
|
xoonips
|
Deserialization of untrusted data vulnerability in XooNIps 3.49 and earlier allows remote attackers to execute arbitrary code via unspecified vectors.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-5664
|
2024-11-21 14:34 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198425
|
5.4 |
MEDIUM
Network
|
riken
|
xoonips
|
Stored cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5663
|
2024-11-21 14:34 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198426
|
5.4 |
MEDIUM
Network
|
riken
|
xoonips
|
Reflected cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5662
|
2024-11-21 14:34 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198427
|
8.8 |
HIGH
Network
|
riken
|
xoonips
|
SQL injection vulnerability in the XooNIps 3.49 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2020-5659
|
2024-11-21 14:34 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198428
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
melsec_iq-r00_firmware melsec_iq-r01_firmware melsec_iq-r02_firmware melsec_iq-r04_firmware melsec_iq-r16_firmware melsec_iq-r08_firmware melsec_iq-r32_firmware melsec_iq-r120_fi…
|
Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/08/16/32/120(EN)CPU Firmware versions from '35' to '51') al…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-5666
|
2024-11-21 14:34 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198429
|
7.8 |
HIGH
Local
|
nagios
|
nagios_xi
|
Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, resulting in low-privileged users being able to write to…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-5796
|
2024-11-21 14:34 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198430
|
7.5 |
HIGH
Network
|
valvesoftware
|
game_networking_sockets
|
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConnectionTransportUDPBase::Received_Data(), leading to an exception thrown from li…
|
NVD-CWE-noinfo
|
CVE-2020-6019
|
2024-11-21 14:34 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|