|
210451
|
7.5 |
HIGH
Network
|
wibu
|
codemeter
|
An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packets containing data from the heap.
|
-
|
CVE-2020-16233
|
2024-11-21 14:06 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210452
|
7.5 |
HIGH
Network
|
gallagher
|
command_centre
|
It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out-of-bounds buffer access. Affected versions are v8.20 prior to v8.20.1166(MR3),…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-16101
|
2024-11-21 14:06 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210453
|
7.5 |
HIGH
Network
|
gallagher
|
command_centre
|
It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websocket thread due to improper shutdown of closed websocket connections, preventing…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2020-16100
|
2024-11-21 14:06 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210454
|
4.3 |
MEDIUM
Network
|
gallagher
|
command_centre
|
In Gallagher Command Centre v8.20 prior to v8.20.1093(MR2) it is possible to create Guard Tour events that when accessed via things like reporting cause clients to temporarily hang or disconnect.
|
NVD-CWE-noinfo
|
CVE-2020-16099
|
2024-11-21 14:06 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210455
|
9.8 |
CRITICAL
Network
|
gallagher
|
command_centre
|
It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior to v8.20.1166(MR3), versions of 8.10 prior to v8.…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-16098
|
2024-11-21 14:06 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210456
|
4.6 |
MEDIUM
Physics
|
gallagher
|
command_centre
|
On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed in v8.10.1211(MR5)), v8.00 prior to vGR8.00.165 (Distribute…
|
NVD-CWE-noinfo
|
CVE-2020-16097
|
2024-11-21 14:06 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210457
|
7.7 |
HIGH
Network
|
gallagher
|
command_centre
|
In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to 7.80.960(MR2), 7.70 and earlier, any operator account has a…
|
NVD-CWE-noinfo
|
CVE-2020-16096
|
2024-11-21 14:06 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210458
|
6.5 |
MEDIUM
Adjacent
|
philips
|
patient_information_center_ix
|
In Patient Information Center iX (PICiX) Versions C.02, C.03, the
software parses a formatted message or structure but does not handle or
incorrectly handles a length field that is inconsistent wit…
|
-
|
CVE-2020-16224
|
2024-11-21 14:06 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210459
|
4.3 |
MEDIUM
Adjacent
|
philips
|
performancebridge_focal_point patient_information_center_ix
|
In Patient Information Center iX (PICiX) Versions C.02, C.03,
PerformanceBridge Focal Point Version A.01, the product receives input
that is expected to be well-formed (i.e., to comply with a certa…
|
-
|
CVE-2020-16220
|
2024-11-21 14:06 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210460
|
6.8 |
MEDIUM
Physics
|
philips
|
patient_information_center_ix
|
In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource. …
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-16212
|
2024-11-21 14:06 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|