|
197711
|
6.5 |
MEDIUM
Network
|
bufferlist_project debian
|
bufferlist debian_linux
|
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can becom…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-8244
|
2024-11-21 14:38 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197712
|
9.8 |
CRITICAL
Network
|
ui
|
edgemax_firmware
|
A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be guessed, enabling the attacker to obtain high privileges and…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-8234
|
2024-11-21 14:38 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197713
|
6.8 |
MEDIUM
Network
|
nextcloud
|
desktop
|
Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.
|
CWE-22
Path Traversal
|
CVE-2020-8227
|
2024-11-21 14:38 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197714
|
5.4 |
MEDIUM
Network
|
nextcloud
|
desktop
|
A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8189
|
2024-11-21 14:38 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197715
|
6.5 |
MEDIUM
Network
|
mongodb
|
mongodb
|
A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue aff…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-7923
|
2024-11-21 14:38 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197716
|
8.8 |
HIGH
Network
|
ui opensuse
|
edgeswitch_firmware leap backports_sle
|
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to esca…
|
CWE-78
OS Command
|
CVE-2020-8233
|
2024-11-21 14:38 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197717
|
6.5 |
MEDIUM
Network
|
ui
|
edgeswitch_firmware
|
An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could obtain unauthorized information through SNMP community pages.
|
CWE-200
Information Exposure
|
CVE-2020-8232
|
2024-11-21 14:38 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197718
|
5.5 |
MEDIUM
Local
|
nextcloud
|
desktop
|
A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-8230
|
2024-11-21 14:38 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197719
|
5.8 |
MEDIUM
Network
|
phpbb
|
phpbb
|
A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-8226
|
2024-11-21 14:38 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197720
|
9.8 |
CRITICAL
Network
|
citrix
|
xenmobile_server
|
Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows acc…
|
CWE-863
Incorrect Authorization
|
CVE-2020-8212
|
2024-11-21 14:38 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|