|
209881
|
6.8 |
MEDIUM
Physics
|
juniper
|
junos
|
On Juniper Networks EX and QFX Series, an authentication bypass vulnerability may allow a user connected to the console port to login as root without any password. This issue might only occur in cert…
|
CWE-287
Improper Authentication
|
CVE-2020-1618
|
2024-11-21 14:11 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209882
|
7.5 |
HIGH
Network
|
juniper
|
junos
|
This issue occurs on Juniper Networks Junos OS devices which do not support Advanced Forwarding Interface (AFI) / Advanced Forwarding Toolkit (AFT). Devices using AFI and AFT are not exploitable to t…
|
CWE-665
Improper Initialization
|
CVE-2020-1617
|
2024-11-21 14:11 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209883
|
5.3 |
MEDIUM
Network
|
juniper
|
virtual_advanced_threat_protection advanced_threat_protection
|
Due to insufficient server-side login attempt limit enforcement, a vulnerability in the SSH login service of Juniper Networks Juniper Advanced Threat Prevention (JATP) Series and Virtual JATP (vJATP)…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-1616
|
2024-11-21 14:11 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209884
|
9.8 |
CRITICAL
Network
|
paloaltonetworks
|
pan-os
|
A format string vulnerability in the Varrcvr daemon of PAN-OS on PA-7000 Series devices with a Log Forwarding Card (LFC) allows remote attackers to crash the daemon creating a denial of service condi…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2020-1992
|
2024-11-21 14:11 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209885
|
4.4 |
MEDIUM
Local
|
paloaltonetworks
|
pan-os vm-series
|
TechSupport files generated on Palo Alto Networks VM Series firewalls for Microsoft Azure platform configured with high availability (HA) inadvertently collect Azure dashboard service account credent…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-1978
|
2024-11-21 14:11 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209886
|
5.4 |
MEDIUM
Network
|
redhat quarkus
|
keycloak quarkus
|
A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does n…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-1728
|
2024-11-21 14:11 |
2020-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209887
|
6.1 |
MEDIUM
Network
|
apache fedoraproject debian canonical opensuse netapp broadcom oracle
|
http_server fedora debian_linux ubuntu_linux leap oncommand_unified_manager_core_package brocade_fabric_operating_system sd-wan_aware instantis_enterprisetrack communicatio…
|
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL…
|
CWE-601
Open Redirect
|
CVE-2020-1927
|
2024-11-21 14:11 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209888
|
6.5 |
MEDIUM
Network
|
apache
|
druid
|
When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines if…
|
CWE-74
Injection
|
CVE-2020-1958
|
2024-11-21 14:11 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209889
|
5.3 |
MEDIUM
Adjacent
|
apache oracle netapp
|
cxf peoplesoft_enterprise_peopletools communications_diameter_signaling_router communications_session_report_manager communications_element_manager enterprise_manager_base_platform …
|
Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationMa…
|
NVD-CWE-noinfo
|
CVE-2020-1954
|
2024-11-21 14:11 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209890
|
5.3 |
MEDIUM
Network
|
apache fedoraproject debian canonical opensuse oracle
|
http_server fedora debian_linux ubuntu_linux leap instantis_enterprisetrack communications_element_manager enterprise_manager_ops_center communications_session_report_manager<…
|
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2020-1934
|
2024-11-21 14:11 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|