|
210571
|
7.5 |
HIGH
Network
|
grin
|
grin
|
Grin 3.0.0 before 4.0.0 has insufficient validation of data related to Mimblewimble.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-15899
|
2024-11-21 14:06 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210572
|
9.8 |
CRITICAL
Network
|
artifex canonical opensuse
|
ghostscript ubuntu_linux leap
|
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'po…
|
CWE-787 CWE-191
Out-of-bounds Write Integer Underflow (Wrap or Wraparound)
|
CVE-2020-15900
|
2024-11-21 14:06 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210573
|
5.3 |
MEDIUM
Local
|
qemu debian canonical
|
qemu debian_linux ubuntu_linux
|
hw/net/xgmac.c in the XGMAC Ethernet controller in QEMU before 07-20-2020 has a buffer overflow. This occurs during packet transmission and affects the highbank and midway emulated machines. A guest …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-15863
|
2024-11-21 14:06 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210574
|
9.9 |
CRITICAL
Network
|
rconfig
|
rconfig
|
rConfig 3.9.5 could allow a remote authenticated attacker to execute arbitrary code on the system, because of an error in the search.crud.php script. An attacker could exploit this vulnerability usin…
|
NVD-CWE-noinfo
|
CVE-2020-15715
|
2024-11-21 14:06 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210575
|
8.8 |
HIGH
Network
|
rconfig
|
rconfig
|
rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.crud.php script using the custom_Location parameter, which could allow t…
|
CWE-89
SQL Injection
|
CVE-2020-15714
|
2024-11-21 14:06 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210576
|
8.8 |
HIGH
Network
|
rconfig
|
rconfig
|
rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.php script using the sortBy parameter, which could allow the attacker to…
|
CWE-89
SQL Injection
|
CVE-2020-15713
|
2024-11-21 14:06 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210577
|
4.3 |
MEDIUM
Network
|
rconfig
|
rconfig
|
rConfig 3.9.5 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a crafted request to the ajaxGetFileByPath.php script containing hexadecimal en…
|
CWE-22
Path Traversal
|
CVE-2020-15712
|
2024-11-21 14:06 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210578
|
9.8 |
CRITICAL
Network
|
openbsd
|
openbsd
|
iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for checking whether a public key matches.
|
CWE-287
Improper Authentication
|
CVE-2020-16088
|
2024-11-21 14:06 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210579
|
6.5 |
MEDIUM
Network
|
kde debian
|
kmail debian_linux
|
KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-15954
|
2024-11-21 14:06 |
2020-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210580
|
7.4 |
HIGH
Network
|
libetpan_project libmailcore fedoraproject debian
|
libetpan mailcore2 fedora debian_linux
|
LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the clien…
|
CWE-74
Injection
|
CVE-2020-15953
|
2024-11-21 14:06 |
2020-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|