|
210681
|
5.4 |
MEDIUM
Network
|
combodo
|
itop
|
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, by modifying target browser local storage, an XSS can be generated in the iTop console breadcrumb. Thi…
|
-
|
CVE-2020-15221
|
2024-11-21 14:05 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210682
|
6.1 |
MEDIUM
Network
|
combodo
|
itop
|
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, two cookies are created for the same session, which leads to a possibility to steal user session. This…
|
-
|
CVE-2020-15220
|
2024-11-21 14:05 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210683
|
4.3 |
MEDIUM
Network
|
combodo
|
itop
|
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, when a download error is triggered in the user portal, an SQL query is displayed to the user. This is …
|
-
|
CVE-2020-15219
|
2024-11-21 14:05 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210684
|
6.8 |
MEDIUM
Network
|
combodo
|
itop
|
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is visible after deconnection by using the browser back …
|
-
|
CVE-2020-15218
|
2024-11-21 14:05 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210685
|
7.0 |
HIGH
Local
|
bitdefender
|
hypervisor_introspection
|
Compiler Optimization Removal or Modification of Security-critical Code vulnerability in IntPeParseUnwindData() results in multiple dereferences to the same pointer. If the pointer is located in memo…
|
NVD-CWE-Other
|
CVE-2020-15294
|
2024-11-21 14:05 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210686
|
5.5 |
MEDIUM
Local
|
bitdefender
|
hypervisor_introspection
|
Memory corruption in IntLixCrashDumpDmesg, IntLixTaskFetchCmdLine, IntLixFileReadDentry and IntLixFileGetPath due to insufficient guest-data input validation may lead to denial of service conditions.
|
CWE-20
Improper Input Validation
|
CVE-2020-15293
|
2024-11-21 14:05 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210687
|
5.5 |
MEDIUM
Local
|
bitdefender
|
hypervisor_introspection
|
Lack of validation on data read from guest memory in IntPeGetDirectory, IntPeParseUnwindData, IntLogExceptionRecord, IntKsymExpandSymbol and IntLixTaskDumpTree may lead to out-of-bounds read or it co…
|
CWE-20
Improper Input Validation
|
CVE-2020-15292
|
2024-11-21 14:05 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210688
|
4.3 |
MEDIUM
Network
|
broadcom
|
fabric_operating_system
|
Brocade Fabric OS versions before v9.0.0 and after version v8.1.0, configured in Virtual Fabric mode contain a weakness in the ldap implementation that could allow a remote ldap user to login in the …
|
NVD-CWE-noinfo
|
CVE-2020-15376
|
2024-11-21 14:05 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210689
|
6.7 |
MEDIUM
Local
|
broadcom
|
fabric_operating_system
|
Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an improper input validation weakness in the command line interface when secccrypptocfg is invoked. T…
|
CWE-20
Improper Input Validation
|
CVE-2020-15375
|
2024-11-21 14:05 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210690
|
9.8 |
CRITICAL
Network
|
askey
|
ap5100w_firmware
|
Network Analysis functionality in Askey AP5100W_Dual_SIG_1.01.097 and all prior versions allows remote attackers to execute arbitrary commands via a shell metacharacter in the ping, traceroute, or ro…
|
CWE-78
OS Command
|
CVE-2020-15357
|
2024-11-21 14:05 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|