|
199611
|
5.5 |
MEDIUM
Local
|
mcafee
|
endpoint_security
|
Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security features via unauthori…
|
CWE-863
Incorrect Authorization
|
CVE-2020-7251
|
2024-11-21 14:36 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199612
|
6.1 |
MEDIUM
Network
|
codologic
|
codoforum
|
Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lack the HttpOnly flag. The impact is account takeove…
|
CWE-79 CWE-732
Cross-site Scripting Incorrect Permission Assignment for Critical Resource
|
CVE-2020-7051
|
2024-11-21 14:36 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199613
|
9.8 |
CRITICAL
Network
|
hp
|
linuxki
|
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
|
NVD-CWE-noinfo
|
CVE-2020-7209
|
2024-11-21 14:36 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199614
|
6.1 |
MEDIUM
Network
|
hp
|
linuxki
|
LinuxKI v6.0-1 and earlier is vulnerable to an XSS which is resolved in release 6.0-2.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7208
|
2024-11-21 14:36 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199615
|
6.2 |
MEDIUM
Network
|
digi
|
connectport_lts_32_mei_bios connectport_lts_32_mei_firmware
|
Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2. Multiple cross-site scripting vulnerabilities exist that could allow an attacker to cause …
|
CWE-79
Cross-site Scripting
|
CVE-2020-6973
|
2024-11-21 14:36 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199616
|
4.9 |
MEDIUM
Network
|
digi
|
connectport_lts_32_mei_bios connectport_lts_32_mei_firmware
|
Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2. Successful exploitation of this vulnerability could allow an attacker to upload a maliciou…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-6975
|
2024-11-21 14:36 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199617
|
7.5 |
HIGH
Network
|
dovecot fedoraproject
|
dovecot fedora
|
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login in…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-7046
|
2024-11-21 14:36 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199618
|
7.5 |
HIGH
Network
|
opensuse
|
wicked
|
An ni_dhcp4_fsm_process_dhcp4_packet memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets with a different client-id.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-7217
|
2024-11-21 14:36 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199619
|
9.1 |
CRITICAL
Network
|
php tenable oracle opensuse debian
|
php tenable.sc communications_diameter_signaling_router leap debian_linux
|
When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause functi…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-7060
|
2024-11-21 14:36 |
2020-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199620
|
9.1 |
CRITICAL
Network
|
php tenable oracle opensuse debian
|
php tenable.sc communications_diameter_signaling_router leap debian_linux
|
When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-7059
|
2024-11-21 14:36 |
2020-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|