|
210691
|
8.8 |
HIGH
Network
|
squid-cache fedoraproject
|
squid fedora
|
An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can succeed against the HTTP cache. The client sends an…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-15049
|
2024-11-21 14:04 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210692
|
8.8 |
HIGH
Network
|
prestosql
|
presto
|
In Presto before version 337, authenticated users can bypass authorization checks by directly accessing internal APIs. This impacts Presto server installations with secure internal communication conf…
|
NVD-CWE-Other
|
CVE-2020-15087
|
2024-11-21 14:04 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210693
|
6.1 |
MEDIUM
Local
|
mirumee
|
saleor
|
In Saleor Storefront before version 2.10.3, request data used to authenticate customers was inadvertently cached in the browser's local storage mechanism, including credentials. A malicious user with…
|
-
|
CVE-2020-15085
|
2024-11-21 14:04 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210694
|
9.1 |
CRITICAL
Network
|
auth0
|
express-jwt
|
In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in the configuration, wi…
|
CWE-863
Incorrect Authorization
|
CVE-2020-15084
|
2024-11-21 14:04 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210695
|
7.8 |
HIGH
Local
|
arswp
|
windows_cleanup_assistant
|
In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input value…
|
CWE-20
Improper Input Validation
|
CVE-2020-14957
|
2024-11-21 14:04 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210696
|
7.8 |
HIGH
Local
|
arswp
|
windows_cleanup_assistant
|
In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input value…
|
CWE-20
Improper Input Validation
|
CVE-2020-14956
|
2024-11-21 14:04 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210697
|
9.8 |
CRITICAL
Network
|
sophos
|
xg_firewall_firmware
|
Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-15069
|
2024-11-21 14:04 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210698
|
6.5 |
MEDIUM
Network
|
iball
|
wrb303n_firmware
|
iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP addresses.
|
CWE-352
Origin Validation Error
|
CVE-2020-15043
|
2024-11-21 14:04 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210699
|
5.5 |
MEDIUM
Local
|
jiangmin
|
jiangmin_antivirus
|
In Jiangmin Antivirus 16.0.13.129, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values f…
|
CWE-20
Improper Input Validation
|
CVE-2020-14955
|
2024-11-21 14:04 |
2020-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210700
|
6.1 |
MEDIUM
Network
|
nedi
|
nedi
|
NeDi 1.9C is vulnerable to reflected cross-site scripting. The Devices-Config.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in …
|
CWE-79
Cross-site Scripting
|
CVE-2020-15017
|
2024-11-21 14:04 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|