|
212671
|
5.3 |
MEDIUM
Network
|
mbconnectline
|
mbconnect24 mymbconnect24
|
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There is a SSRF in the LDAP access check, allowing an attacker to scan for open ports.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-12529
|
2024-11-21 13:59 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212672
|
7.7 |
HIGH
Network
|
mbconnectline
|
mbconnect24 mymbconnect24
|
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access validation allows a logged in user to kill web2go sessions in …
|
CWE-269
Improper Privilege Management
|
CVE-2020-12528
|
2024-11-21 13:59 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212673
|
6.5 |
MEDIUM
Network
|
mbconnectline helmholz
|
mbconnect24 mymbconnect24 myrex24.virtual myrex24
|
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to s…
|
-
|
CVE-2020-12527
|
2024-11-21 13:59 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212674
|
8.2 |
HIGH
Network
|
apache fedoraproject
|
xmlgraphics_commons fedora
|
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could…
|
CWE-20 CWE-918
Improper Input Validation Server-Side Request Forgery (SSRF)
|
CVE-2020-11988
|
2024-11-21 13:59 |
2021-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212675
|
8.2 |
HIGH
Network
|
apache fedoraproject oracle debian
|
batik fedora enterprise_repository retail_back_office weblogic_server retail_order_broker retail_returns_management retail_central_office retail_point-of-service instantis_…
|
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulne…
|
CWE-20 CWE-918
Improper Input Validation Server-Side Request Forgery (SSRF)
|
CVE-2020-11987
|
2024-11-21 13:59 |
2021-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212676
|
6.7 |
MEDIUM
Local
|
intel
|
bmc_firmware
|
Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow a privileged user to potentially enable escalation of privilege v…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-12374
|
2024-11-21 13:59 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212677
|
5.5 |
MEDIUM
Local
|
intel
|
graphics_drivers
|
Untrusted pointer dereference in some Intel(R) Graphics Drivers before versions 15.33.51.5146, 15.45.32.5145, 15.36.39.5144 and 15.40.46.5143 may allow an authenticated user to potentially denial of …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-12365
|
2024-11-21 13:59 |
2021-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212678
|
5.5 |
MEDIUM
Local
|
intel
|
graphics_drivers
|
Out-of-bounds write in some Intel(R) Graphics Drivers before version 15.36.39.5143 may allow an authenticated user to potentially enable denial of service via local access.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12386
|
2024-11-21 13:59 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212679
|
7.8 |
HIGH
Local
|
intel
|
graphics_drivers
|
Improper input validation in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable escalation of privilege via local access.
|
CWE-20
Improper Input Validation
|
CVE-2020-12385
|
2024-11-21 13:59 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212680
|
7.8 |
HIGH
Local
|
intel
|
graphics_drivers
|
Improper access control in some Intel(R) Graphics Drivers before version 26.20.100.8476 may allow an authenticated user to potentially enable an escalation of privilege via local access.
|
NVD-CWE-Other
|
CVE-2020-12384
|
2024-11-21 13:59 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|