|
197531
|
7.2 |
HIGH
Network
|
huawei
|
fusioncompute
|
Huawei FusionCompute versions 6.5.1 and 8.0.0 have a command injection vulnerability. An authenticated, remote attacker can craft specific request to exploit this vulnerability. Due to insufficient v…
|
CWE-77
Command Injection
|
CVE-2020-9116
|
2024-11-21 14:40 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197532
|
7.2 |
HIGH
Network
|
huawei
|
manageone
|
ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command injection vulnerability. An attacker with high privileges may exploit this vul…
|
CWE-20 CWE-77
Improper Input Validation Command Injection
|
CVE-2020-9115
|
2024-11-21 14:40 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197533
|
6.7 |
MEDIUM
Local
|
huawei
|
mate_30_firmware
|
HUAWEI Mate 30 versions earlier than 10.1.0.159(C00E159R7P2) have a vulnerability of improper buffer operation. Due to improper restrictions, local attackers with high privileges can exploit the vuln…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-9129
|
2024-11-21 14:40 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197534
|
6.7 |
MEDIUM
Local
|
huawei
|
nip6300_firmware nip6600_firmware secospace_usg6300_firmware secospace_usg6500_firmware secospace_usg6600_firmware usg9500_firmware
|
Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some malicious codes in some files of the affected produc…
|
CWE-20 CWE-77
Improper Input Validation Command Injection
|
CVE-2020-9127
|
2024-11-21 14:40 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197535
|
4.4 |
MEDIUM
Local
|
huawei
|
fusioncompute
|
FusionCompute versions 8.0.0 have an insecure encryption algorithm vulnerability. Attackers with high permissions can exploit this vulnerability to cause information leak.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-9128
|
2024-11-21 14:40 |
2020-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197536
|
6.5 |
MEDIUM
Network
|
netflix
|
dispatch
|
The Access Control issues include allowing a regular user to view a restricted incident, user role escalation to admin, users adding themselves as a participant in a restricted incident, and users ab…
|
NVD-CWE-Other
|
CVE-2020-9300
|
2024-11-21 14:40 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197537
|
5.4 |
MEDIUM
Network
|
netflix
|
dispatch
|
There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Priority, Incident Type, Tag Type, and Incident Filter. This …
|
CWE-79
Cross-site Scripting
|
CVE-2020-9299
|
2024-11-21 14:40 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197538
|
7.5 |
HIGH
Network
|
oleacorner
|
olea_gift_on_order
|
The Module Olea Gift On Order module through 5.0.8 for PrestaShop enables an unauthenticated user to read arbitrary files on the server via getfile.php?file=/.. directory traversal.
|
CWE-22
Path Traversal
|
CVE-2020-9368
|
2024-11-21 14:40 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197539
|
5.5 |
MEDIUM
Local
|
cryptopro
|
csp
|
CryptoPro CSP through 5.0.0.10004 on 64-bit platforms allows local users with the SeChangeNotifyPrivilege right to cause denial of service because user-mode input is mishandled during process creatio…
|
NVD-CWE-noinfo
|
CVE-2020-9361
|
2024-11-21 14:40 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197540
|
7.8 |
HIGH
Local
|
cryptopro
|
csp
|
CryptoPro CSP through 5.0.0.10004 on 32-bit platforms allows Local Privilege Escalation (by local users with the SeChangeNotifyPrivilege right) because user-mode input is mishandled during process cr…
|
NVD-CWE-noinfo
|
CVE-2020-9331
|
2024-11-21 14:40 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|