|
210191
|
6.1 |
MEDIUM
Network
|
linuxfoundation redhat fedoraproject canonical debian
|
ceph ceph_storage openshift_container_platform fedora ubuntu_linux debian_linux
|
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization o…
|
CWE-79
Cross-site Scripting
|
CVE-2020-1760
|
2024-11-21 14:11 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210192
|
6.5 |
MEDIUM
Local
|
libslirp_project fedoraproject debian opensuse canonical
|
libslirp fedora debian_linux leap ubuntu_linux
|
A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.
|
CWE-416
Use After Free
|
CVE-2020-1983
|
2024-11-21 14:11 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210193
|
8.1 |
HIGH
Network
|
redhat
|
undertow jboss_fuse jboss_enterprise_application_platform single_sign-on jboss_data_grid openshift_application_runtimes
|
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes serv…
|
CWE-20
Improper Input Validation
|
CVE-2020-1757
|
2024-11-21 14:11 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210194
|
7.5 |
HIGH
Network
|
linuxfoundation redhat
|
ceph ceph_storage
|
A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated a…
|
CWE-22
Path Traversal
|
CVE-2020-1699
|
2024-11-21 14:11 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210195
|
7.5 |
HIGH
Network
|
openssl debian freebsd fedoraproject oracle netapp broadcom opensuse jdedwards tenable
|
openssl debian_linux freebsd fedora peoplesoft_enterprise_peopletools jd_edwards_world_security enterprise_manager_ops_center mysql enterprise_manager_base_platform mysql_e…
|
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signat…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-1967
|
2024-11-21 14:11 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210196
|
5.3 |
MEDIUM
Adjacent
|
huawei
|
honor_v20_firmware
|
Huawei smartphones Honor V20 with versions earlier than 10.0.0.179(C636E3R4P3),versions earlier than 10.0.0.180(C185E3R3P3),versions earlier than 10.0.0.180(C432E10R3P4) have an information disclosur…
|
CWE-287
Improper Authentication
|
CVE-2020-1803
|
2024-11-21 14:11 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210197
|
7.0 |
HIGH
Local
|
gnu redhat canonical
|
glibc enterprise_linux ubuntu_linux
|
An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when stor…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-1751
|
2024-11-21 14:11 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210198
|
9.8 |
CRITICAL
Network
|
apache
|
heron
|
It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to prevent the instantiation of arbitrary types, resu…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-1964
|
2024-11-21 14:11 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210199
|
8.6 |
HIGH
Network
|
juniper
|
junos junos_os_evolved
|
In a certain condition, receipt of a specific BGP UPDATE message might cause Juniper Networks Junos OS and Junos OS Evolved devices to advertise an invalid BGP UPDATE message to other peers, causing …
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-1632
|
2024-11-21 14:11 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210200
|
5.3 |
MEDIUM
Network
|
libssh canonical netapp redhat fedoraproject oracle
|
libssh ubuntu_linux cloud_backup enterprise_linux fedora mysql_workbench
|
A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been f…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-1730
|
2024-11-21 14:11 |
2020-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|