|
210711
|
8.1 |
HIGH
Network
|
redhat
|
keycloak
|
It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user …
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2020-14389
|
2024-11-21 14:03 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210712
|
7.5 |
HIGH
Network
|
redhat
|
keycloak
|
A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resources endpoint applies a transformation of the url path to the f…
|
CWE-22
Path Traversal
|
CVE-2020-14366
|
2024-11-21 14:03 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210713
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_reader
|
Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can execute local files and bypass the security dialog.
|
NVD-CWE-noinfo
|
CVE-2020-14425
|
2024-11-21 14:03 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210714
|
5.5 |
MEDIUM
Local
|
samba opensuse fedoraproject debian
|
samba leap fedora debian_linux
|
A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-14323
|
2024-11-21 14:03 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210715
|
3.1 |
LOW
Network
|
oracle
|
retail_customer_management_and_segmentation_foundation
|
Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Segment). Supported versions that are affected are 18.0 and 19.0. …
|
NVD-CWE-noinfo
|
CVE-2020-14731
|
2024-11-21 14:03 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210716
|
4.9 |
MEDIUM
Network
|
oracle netapp fedoraproject
|
mysql oncommand_workflow_automation snapcenter_server oncommand_insight active_iq_unified_manager fedora
|
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Easi…
|
NVD-CWE-noinfo
|
CVE-2020-14672
|
2024-11-21 14:03 |
2020-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210717
|
6.6 |
MEDIUM
Network
|
spice_project redhat canonical debian opensuse
|
spice enterprise_linux ubuntu_linux debian_linux enterprise_linux_eus leap enterprise_linux_aus openstack enterprise_linux_tus enterprise_linux_update_services_for_sap_solu…
|
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affe…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-14355
|
2024-11-21 14:03 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210718
|
8.8 |
HIGH
Local
|
dpdk opensuse canonical
|
data_plane_development_kit leap ubuntu_linux
|
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data function leads to a buffer overflow allowing an attacker in a virtual machine to wri…
|
-
|
CVE-2020-14374
|
2024-11-21 14:03 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210719
|
3.3 |
LOW
Local
|
dpdk opensuse canonical
|
data_plane_development_kit leap ubuntu_linux
|
An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could c…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2020-14378
|
2024-11-21 14:03 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210720
|
7.1 |
HIGH
Local
|
dpdk canonical opensuse
|
data_plane_development_kit ubuntu_linux leap
|
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A complete lack of validation of attacker-controlled parameters can lead to a buffer over read. The results of the over read a…
|
-
|
CVE-2020-14377
|
2024-11-21 14:03 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|