|
208581
|
4.4 |
MEDIUM
Local
|
linux fedoraproject redhat
|
linux_kernel fedora enterprise_linux messaging_realtime_grid openshift_container_platform
|
A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC. This fl…
|
-
|
CVE-2020-25639
|
2024-11-21 14:18 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208582
|
7.6 |
HIGH
Physics
|
gnu redhat fedoraproject netapp
|
grub2 enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux enterprise_linux_server_tus enterprise_linux_server_eus fedora ontap_select_deploy_administration_…
|
A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assumes the USB device is providing sane values. If pr…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-25647
|
2024-11-21 14:18 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208583
|
8.2 |
HIGH
Local
|
gnu redhat fedoraproject netapp
|
grub2 enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux enterprise_linux_server_tus enterprise_linux_server_eus fedora ontap_select_deploy_administration_…
|
A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded lead…
|
CWE-416
Use After Free
|
CVE-2020-25632
|
2024-11-21 14:18 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208584
|
6.1 |
MEDIUM
Network
|
blackboard
|
collaborate_ultra
|
Blackboard Collaborate Ultra 20.02 is affected by a cross-site scripting (XSS) vulnerability. The XSS payload will execute on the class room, which leads to stealing cookies from users who join the c…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25902
|
2024-11-21 14:18 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208585
|
8.8 |
HIGH
Network
|
fontforge
|
fontforge
|
An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens. This flaw allows an attacker to manipulate the memory allo…
|
-
|
CVE-2020-25690
|
2024-11-21 14:18 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208586
|
5.9 |
MEDIUM
Network
|
agora
|
video_software_development_kit
|
Cleartext transmission of sensitive information in Agora Video SDK prior to 3.1 allows a remote attacker to obtain access to audio and video of any ongoing Agora video call through observation of cle…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-25605
|
2024-11-21 14:18 |
2021-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208587
|
7.5 |
HIGH
Network
|
oclean
|
oclean
|
Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using XOR with a hardcode…
|
CWE-798 CWE-327
Use of Hard-coded Credentials Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-25493
|
2024-11-21 14:18 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208588
|
7.5 |
HIGH
Network
|
realtek
|
rtl8195a_firmware
|
The function ClientEAPOLKeyRecvd() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an rtl_memcpy() op…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-25857
|
2024-11-21 14:18 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208589
|
8.1 |
HIGH
Network
|
realtek
|
rtl8195a_firmware
|
The function DecWPA2KeyData() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an rtl_memcpy() operati…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-25856
|
2024-11-21 14:18 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208590
|
8.1 |
HIGH
Network
|
realtek
|
rtl8195a_firmware
|
The function AES_UnWRAP() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for a memcpy() operation, resul…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-25855
|
2024-11-21 14:18 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|