|
197521
|
6.5 |
MEDIUM
Adjacent
|
huawei
|
nip6800_firmware secospace_usg6600_firmware usg9500_firmware
|
There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9500. The software reads data past the end of the intended buffer when parsing DHCP messages includi…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-9201
|
2024-11-21 14:40 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197522
|
7.8 |
HIGH
Local
|
huawei
|
imanager_neteco_6000
|
There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files.…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-9200
|
2024-11-21 14:40 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197523
|
6.7 |
MEDIUM
Local
|
huawei
|
cloudengine_12800_firmware cloudengine_5800_firmware cloudengine_6800_firmware cloudengine_7800_firmware
|
There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 and CloudEngine 7800. Due to insufficient input validation, a local attacker with…
|
CWE-20
Improper Input Validation
|
CVE-2020-9137
|
2024-11-21 14:40 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197524
|
7.5 |
HIGH
Network
|
huawei
|
cloudengine_1800v
|
CloudEngine 1800V versions V100R019C10SPC500 has a resource management error vulnerability. Remote unauthorized attackers could send specific types of messages to the device, resulting in the message…
|
NVD-CWE-Other
|
CVE-2020-9120
|
2024-11-21 14:40 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197525
|
6.2 |
MEDIUM
Physics
|
huawei
|
mate_10_firmware mate_30_firmware mate_30_pro_firmware p40_firmware p40_pro_firmware
|
There is a privilege escalation vulnerability on some Huawei smart phones due to design defects. The attacker needs to physically contact the mobile phone and obtain higher privileges, and execute re…
|
NVD-CWE-noinfo
|
CVE-2020-9119
|
2024-11-21 14:40 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197526
|
6.1 |
MEDIUM
Network
|
uncannyowl
|
tin_canny_reporting_for_learndash
|
Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Owl Tin Canny LearnDash Reporting before 3.4.4 allows authenticated remote attackers to inject arbitrary web script or HTML via the sear…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9439
|
2024-11-21 14:40 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197527
|
8.8 |
HIGH
Network
|
linuxfoundation
|
spinnaker
|
Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpE…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-9301
|
2024-11-21 14:40 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197528
|
7.8 |
HIGH
Local
|
huawei
|
honor_20_pro_firmware mate_20_firmware mate_20_pro_firmware mate_20_x_firmware p30_firmware p30_pro_firmware hima-l29c_firmware laya-al00ep_firmware princeton-al10b_firmware
|
There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overfl…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-9247
|
2024-11-21 14:40 |
2020-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197529
|
7.8 |
HIGH
Local
|
huawei
|
nova_4_firmware sydneym-al00_firmware
|
HUAWEI nova 4 versions earlier than 10.0.0.165(C01E34R2P4) and SydneyM-AL00 versions earlier than 10.0.0.165(C00E66R1P5) have an out-of-bounds read and write vulnerability. An attacker with specific …
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-9117
|
2024-11-21 14:40 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197530
|
7.8 |
HIGH
Local
|
huawei
|
fusioncompute
|
FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper privilege management, an attacker with common privilege may access some specific…
|
CWE-269
Improper Privilege Management
|
CVE-2020-9114
|
2024-11-21 14:40 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|