|
196341
|
5.5 |
MEDIUM
Local
|
huawei
|
p30_pro_firmware
|
HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have an out-of-bounds read and write vulnerability. An unauthenticated attacker crafts malformed message with specific parameter and sends…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-9108
|
2024-11-21 14:40 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196342
|
5.5 |
MEDIUM
Local
|
huawei
|
p30_pro_firmware
|
HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have an out-of-bounds read and write vulnerability. An unauthenticated attacker crafts malformed message with specific parameter and sends…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-9107
|
2024-11-21 14:40 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196343
|
4.6 |
MEDIUM
Physics
|
huawei
|
p30_pro_firmware
|
HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have a path traversal vulnerability. The system does not sufficiently validate certain pathname, successful exploit could allow the attack…
|
CWE-22
Path Traversal
|
CVE-2020-9106
|
2024-11-21 14:40 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196344
|
5.5 |
MEDIUM
Local
|
huawei
|
taurus-an00b_firmware
|
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an out-of-bounds read and write vulnerability. Some functions do not verify inputs sufficiently. Attackers can exploit this vulnerabili…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-9091
|
2024-11-21 14:40 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196345
|
7.8 |
HIGH
Local
|
huawei
|
fusionaccess
|
FusionAccess version 6.5.1 has an improper authorization vulnerability. A command is authorized with incorrect privilege. Attackers with other privilege can execute the command to exploit this vulner…
|
NVD-CWE-noinfo
|
CVE-2020-9090
|
2024-11-21 14:40 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196346
|
6.7 |
MEDIUM
Local
|
huawei
|
taurus-an00b_firmware
|
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerabil…
|
CWE-20
Improper Input Validation
|
CVE-2020-9105
|
2024-11-21 14:40 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196347
|
7.5 |
HIGH
Network
|
apache
|
nifi
|
In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However i…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-9491
|
2024-11-21 14:40 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196348
|
7.5 |
HIGH
Network
|
apache
|
nifi
|
In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to create a download token, only when attempting to us…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-9487
|
2024-11-21 14:40 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196349
|
7.5 |
HIGH
Network
|
apache
|
nifi
|
In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON wa…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-9486
|
2024-11-21 14:40 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196350
|
5.4 |
MEDIUM
Network
|
tibco
|
spotfire_server spotfire_desktop spotfire_analytics_platform spotfire_analyst
|
The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, and TIBCO Spotfire Server contains a vuln…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9416
|
2024-11-21 14:40 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|