|
197881
|
5.3 |
MEDIUM
Network
|
ibm
|
security_secret_server
|
IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in fur…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-4327
|
2024-11-21 14:32 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197882
|
6.1 |
MEDIUM
Network
|
ibm
|
security_secret_server
|
IBM Security Secret Server 10.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potent…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4323
|
2024-11-21 14:32 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197883
|
4.3 |
MEDIUM
Network
|
ibm
|
security_secret_server
|
IBM Security Secret Server 10.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this v…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-4322
|
2024-11-21 14:32 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197884
|
2.4 |
LOW
Physics
|
django-basic-auth-ip-whitelist_project
|
django-basic-auth-ip-whitelist
|
In django-basic-auth-ip-whitelist before 0.3.4, a potential timing attack exists on websites where the basic authentication is used or configured, i.e. BASIC_AUTH_LOGIN and BASIC_AUTH_PASSWORD is set…
|
-
|
CVE-2020-4071
|
2024-11-21 14:32 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197885
|
5.3 |
MEDIUM
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 10.6 and 11.1 may use insufficiently random numbers or values in a security context that depends on unpredictable numbers. IBM X-Force ID: 174807.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-4188
|
2024-11-21 14:32 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197886
|
5.3 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center
|
Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers t…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-4028
|
2024-11-21 14:32 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197887
|
6.5 |
MEDIUM
Network
|
freerdp fedoraproject opensuse canonical debian
|
freerdp fedora leap ubuntu_linux debian_linux
|
In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with sessions with color depth < 32 are affected. This is fixed in version 2.1.2.
|
-
|
CVE-2020-4033
|
2024-11-21 14:32 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197888
|
4.3 |
MEDIUM
Network
|
freerdp opensuse fedoraproject canonical debian
|
freerdp leap fedora ubuntu_linux debian_linux
|
In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1…
|
-
|
CVE-2020-4032
|
2024-11-21 14:32 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197889
|
7.5 |
HIGH
Network
|
freerdp fedoraproject opensuse canonical debian
|
freerdp fedora leap ubuntu_linux debian_linux
|
In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility mode with /relax-order-checks are affected. This is fixed in version 2.1.2.
|
-
|
CVE-2020-4031
|
2024-11-21 14:32 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197890
|
6.5 |
MEDIUM
Network
|
freerdp fedoraproject opensuse canonical debian
|
freerdp fedora leap ubuntu_linux debian_linux
|
In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.
|
-
|
CVE-2020-4030
|
2024-11-21 14:32 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|