|
200561
|
7.8 |
HIGH
Local
|
google opensuse
|
guest-oslogin leap
|
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Usi…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-8907
|
2024-11-21 14:39 |
2020-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200562
|
7.8 |
HIGH
Local
|
google opensuse
|
guest-oslogin leap
|
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Usi…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-8903
|
2024-11-21 14:39 |
2020-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200563
|
4.9 |
MEDIUM
Network
|
isc opensuse netapp canonical
|
bind leap steelstore_cloud_integrated_storage ubuntu_linux
|
An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clie…
|
CWE-617
Reachable Assertion
|
CVE-2020-8618
|
2024-11-21 14:39 |
2020-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200564
|
4.9 |
MEDIUM
Network
|
isc fedoraproject opensuse debian canonical netapp
|
bind fedora leap debian_linux ubuntu_linux steelstore_cloud_integrated_storage
|
In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative s…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2020-8619
|
2024-11-21 14:39 |
2020-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200565
|
6.5 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.3 allows SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-8544
|
2024-11-21 14:39 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200566
|
7.5 |
HIGH
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.3 has Improper Input Validation.
|
CWE-20
Improper Input Validation
|
CVE-2020-8543
|
2024-11-21 14:39 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200567
|
5.4 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.3 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8542
|
2024-11-21 14:39 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200568
|
6.8 |
MEDIUM
Network
|
huawei
|
p30_firmware p30_pro_firmware tony-al00b_firmware
|
HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B smartphones with versions earlier than 10.1.0.135(C00E135R2P11); versions earlier than 10.1.0.135(C00E135R2P8), versions earlier than 10.1.0.135 have an improper …
|
CWE-287
Improper Authentication
|
CVE-2020-9076
|
2024-11-21 14:39 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200569
|
6.5 |
MEDIUM
Network
|
huawei
|
secospace_usg6300_firmware secospace_usg6600_firmware usg6300e_firmware
|
Huawei products Secospace USG6300;USG6300E with versions of V500R001C30,V500R001C50,V500R001C60,V500R001C80,V500R005C00,V500R005C10;V600R006C00 have a vulnerability of insufficient input verification…
|
CWE-20
Improper Input Validation
|
CVE-2020-9075
|
2024-11-21 14:39 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200570
|
6.8 |
MEDIUM
Physics
|
intel
|
innovation_engine_firmware
|
Insufficient control flow management in firmware build and signing tool for Intel(R) Innovation Engine before version 1.0.859 may allow an unauthenticated user to potentially enable escalation of pri…
|
NVD-CWE-noinfo
|
CVE-2020-8675
|
2024-11-21 14:39 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|