|
211131
|
9.8 |
CRITICAL
Network
|
apache
|
tomee
|
If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is misconfigured, a JMX port is opened on TCP…
|
NVD-CWE-noinfo
|
CVE-2020-13931
|
2024-11-21 14:02 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211132
|
7.5 |
HIGH
Network
|
hcltech
|
bigfix_platform
|
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-14254
|
2024-11-21 14:02 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211133
|
5.3 |
MEDIUM
Network
|
hcltech
|
bigfix_platform
|
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers …
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-14248
|
2024-11-21 14:02 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211134
|
4.9 |
MEDIUM
Network
|
redhat
|
keycloak
|
A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful authentication, redirects to a Keycloak endpoint that accepts multiple invocations with the use of the…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2020-14302
|
2024-11-21 14:02 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211135
|
9.8 |
CRITICAL
Network
|
hcltech
|
notes
|
A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could all…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-14268
|
2024-11-21 14:02 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211136
|
9.8 |
CRITICAL
Network
|
hcltech
|
domino
|
A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could al…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-14244
|
2024-11-21 14:02 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211137
|
7.5 |
HIGH
Network
|
contiki-ng
|
contiki-ng
|
An issue was discovered in Contiki through 3.0. An Integer Overflow exists in the uIP TCP/IP Stack component when parsing TCP MSS options of IPv4 network packets in uip_process in net/ipv4/uip.c.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-13988
|
2024-11-21 14:02 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211138
|
7.5 |
HIGH
Network
|
uip_project open-iscsi_project siemens
|
uip open-iscsi sentron_3va_com100_firmware sentron_3va_com800_firmware sentron_pac3200_firmware sentron_pac4200_firmware
|
An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_layer_chksum in net…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-13987
|
2024-11-21 14:02 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211139
|
7.5 |
HIGH
Network
|
contiki-os
|
contiki
|
An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when handling RPL extension headers of IPv6 network packets in rpl_remove_header in net/rpl/r…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-13986
|
2024-11-21 14:02 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211140
|
7.5 |
HIGH
Network
|
contiki-os
|
contiki
|
An issue was discovered in Contiki through 3.0. A memory corruption vulnerability exists in the uIP TCP/IP stack component when handling RPL extension headers of IPv6 network packets in rpl_remove_he…
|
CWE-787 CWE-190 CWE-681
Out-of-bounds Write Integer Overflow or Wraparound Incorrect Conversion between Numeric Types
|
CVE-2020-13985
|
2024-11-21 14:02 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|