|
210281
|
6.1 |
MEDIUM
Network
|
mediawiki fedoraproject
|
mediawiki fedora
|
An issue was discovered in MediaWiki 1.34.x before 1.34.4. On Special:Contributions, the NS filter uses unescaped messages as keys in the option key for an HTMLForm specifier. This is vulnerable to a…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25812
|
2024-11-21 14:18 |
2020-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210282
|
5.3 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-25625
|
2024-11-21 14:18 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210283
|
9.8 |
CRITICAL
Network
|
rubetek
|
rv-3406_firmware rv-3409_firmware rv-3411_firmware
|
The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged acc…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-25749
|
2024-11-21 14:18 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210284
|
8.1 |
HIGH
Network
|
rubetek
|
rv-3406_firmware rv-3409_firmware rv-3411_firmware
|
A Cleartext Transmission issue was discovered on Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339). Someone in the middle can intercept and modify the video data from the c…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-25748
|
2024-11-21 14:18 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210285
|
9.4 |
CRITICAL
Network
|
rubetek
|
rv-3406_firmware rv-3409_firmware rv-3411_firmware
|
The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote attacker to gain access to RTSP and ONFIV services without authentication. Thus, …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-25747
|
2024-11-21 14:18 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210286
|
4.7 |
MEDIUM
Local
|
xen fedoraproject debian opensuse
|
xen fedora debian_linux leap
|
An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers between x86 HVM vCPUs. When migrating timers of x86 HVM guests between its vCPUs, the locking model used…
|
CWE-362
Race Condition
|
CVE-2020-25604
|
2024-11-21 14:18 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210287
|
7.8 |
HIGH
Local
|
xen fedoraproject opensuse debian
|
xen fedora leap debian_linux
|
An issue was discovered in Xen through 4.14.x. There are missing memory barriers when accessing/allocating an event channel. Event channels control structures can be accessed lockless as long as the …
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2020-25603
|
2024-11-21 14:18 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210288
|
6.0 |
MEDIUM
Local
|
xen fedoraproject debian opensuse
|
xen fedora debian_linux leap
|
An issue was discovered in Xen through 4.14.x. An x86 PV guest can trigger a host OS crash when handling guest access to MSR_MISC_ENABLE. When a guest accesses certain Model Specific Registers, Xen f…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-25602
|
2024-11-21 14:18 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210289
|
5.5 |
MEDIUM
Local
|
xen debian fedoraproject opensuse
|
xen debian_linux fedora leap
|
An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evtchn_destroy(). In particular, the FIFO event channel model allows guests to have a large number of …
|
NVD-CWE-noinfo
|
CVE-2020-25601
|
2024-11-21 14:18 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210290
|
5.5 |
MEDIUM
Local
|
xen fedoraproject opensuse debian
|
xen fedora leap debian_linux
|
An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit x86 domains. The so called 2-level event channel model imposes different limits on the number of us…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-25600
|
2024-11-21 14:18 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|