|
197101
|
7.5 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
On BIG-IP 15.0.0-15.0.1.1 and 14.1.0-14.1.2.2, while processing specifically crafted traffic using the default 'xnet' driver, Virtual Edition instances hosted in Amazon Web Services (AWS) may experie…
|
NVD-CWE-noinfo
|
CVE-2020-5856
|
2024-11-21 14:34 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197102
|
5.9 |
MEDIUM
Network
|
f5
|
enterprise_manager traffix_signaling_delivery_controller big-iq_centralized_management iworkflow big-ip_access_policy_manager big-ip_local_traffic_manager big-ip_application_acceler…
|
On BIG-IP 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.0-11.6.5.1, the tmm crashes under certain circumstances when using the connector profile if a speci…
|
NVD-CWE-noinfo
|
CVE-2020-5854
|
2024-11-21 14:34 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197103
|
6.1 |
MEDIUM
Network
|
sixapart
|
movable_type
|
Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4603 and earlier (Movable Type 7), Movable Type 6.5.2 and earlier (Movable Type 6.5), Movable Type Advanced 7 r.4603 and ea…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5528
|
2024-11-21 14:34 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197104
|
5.9 |
MEDIUM
Network
|
fujixerox
|
apeosware_management_suite
|
The AWMS Mobile App for Android 2.0.0 to 2.0.5 and for iOS 2.0.0 to 2.0.8 does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensiti…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-5526
|
2024-11-21 14:34 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197105
|
7.4 |
HIGH
Network
|
nttdata ashikagabank sihd-bk shikokubank tohoku-bank naganobank 77bank hokkaidobank hokugin
|
mypallete ashigin ikeda_senshu_bank shikoku_bank tougin nagagin 77_bank dogin hokuriku_bank_portal
|
Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-misma…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-5523
|
2024-11-21 14:34 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197106
|
7.4 |
HIGH
Network
|
fujixerox
|
easy_netprint
|
The kantan netprint App for Android 2.0.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-5522
|
2024-11-21 14:34 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197107
|
7.4 |
HIGH
Network
|
fujixerox
|
easy_netprint
|
The kantan netprint App for iOS 2.0.2 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a cra…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-5521
|
2024-11-21 14:34 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197108
|
7.4 |
HIGH
Network
|
fujixerox
|
netprint
|
The netprint App for iOS 3.2.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted ce…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-5520
|
2024-11-21 14:34 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197109
|
7.9 |
HIGH
Adjacent
|
philips
|
hue_bridge_v2_firmware
|
Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL string during the commissioning phase, resulting in a remote code…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6007
|
2024-11-21 14:34 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197110
|
5.3 |
MEDIUM
Network
|
vmware oracle
|
spring_framework flexcube_private_banking insurance_policy_administration_j2ee insurance_rules_palette retail_service_backbone retail_back_office weblogic_server application_test…
|
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) …
|
CWE-352
Origin Validation Error
|
CVE-2020-5397
|
2024-11-21 14:34 |
2020-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|