|
209581
|
5.4 |
MEDIUM
Network
|
innokasmedical
|
vital_signs_monitor_vc150_firmware
|
Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 A stored cross-site scripting (XSS) vulnerability exists in the affected products that allow an attacker to inject arbitrary web sc…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27262
|
2024-11-21 14:20 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209582
|
5.3 |
MEDIUM
Physics
|
innokasmedical
|
vital_signs_monitor_vc150_firmware
|
Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 HL7 v2.x injection vulnerabilities exist in the affected products that allow physically proximate attackers with a connected barcod…
|
CWE-74
Injection
|
CVE-2020-27260
|
2024-11-21 14:20 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209583
|
8.8 |
HIGH
Network
|
restaurant_reservation_system_project
|
restaurant_reservation_system
|
Restaurant Reservation System 1.0 suffers from an authenticated SQL injection vulnerability, which allows a remote, authenticated attacker to execute arbitrary SQL commands via the date parameter in …
|
CWE-89
SQL Injection
|
CVE-2020-26773
|
2024-11-21 14:20 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209584
|
6.1 |
MEDIUM
Network
|
mozilla
|
firefox
|
When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then redirect the user before navigation occurred to the d…
|
CWE-601
Open Redirect
|
CVE-2020-26979
|
2024-11-21 14:20 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209585
|
6.1 |
MEDIUM
Network
|
mozilla
|
firefox_esr thunderbird firefox
|
Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerabi…
|
NVD-CWE-noinfo
|
CVE-2020-26978
|
2024-11-21 14:20 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209586
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. *Note: This issue only affects F…
|
NVD-CWE-noinfo
|
CVE-2020-26977
|
2024-11-21 14:20 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209587
|
6.5 |
MEDIUM
Network
|
mozilla debian
|
firefox debian_linux
|
When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe …
|
NVD-CWE-noinfo
|
CVE-2020-26976
|
2024-11-21 14:20 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209588
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abusing ambient authori…
|
NVD-CWE-noinfo
|
CVE-2020-26975
|
2024-11-21 14:20 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209589
|
8.8 |
HIGH
Network
|
mozilla
|
firefox_esr thunderbird firefox
|
When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a poten…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-26974
|
2024-11-21 14:20 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209590
|
8.8 |
HIGH
Network
|
mozilla
|
firefox_esr thunderbird firefox
|
Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass. This vulnerability affects Firefox < 84, Thunderbird …
|
NVD-CWE-noinfo
|
CVE-2020-26973
|
2024-11-21 14:20 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|