|
209621
|
4.2 |
MEDIUM
Local
|
cisofy fedoraproject
|
lynis fedora
|
CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log and report file permissions was not working as intended and could be bypassed l…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2020-13882
|
2024-11-21 14:02 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209622
|
8.1 |
HIGH
Adjacent
|
abus
|
secvest_wireless_control_fube50001_firmware
|
The wireless-communication feature of the ABUS Secvest FUBE50001 device does not encrypt sensitive data such as PIN codes or IDs of used proximity chip keys (RFID tokens). This makes it easier for an…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-14157
|
2024-11-21 14:02 |
2020-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209623
|
7.5 |
HIGH
Network
|
golang fedoraproject
|
text fedora
|
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An a…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-14040
|
2024-11-21 14:02 |
2020-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209624
|
7.2 |
HIGH
Network
|
cacti fedoraproject
|
cacti fedora
|
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.
|
CWE-89
SQL Injection
|
CVE-2020-14295
|
2024-11-21 14:02 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209625
|
6.5 |
MEDIUM
Network
|
zammad
|
zammad
|
Zammad before 3.3.1, when Domain Based Assignment is enabled, relies on a claimed e-mail address for authorization decisions. An attacker can register a new account that will have access to all ticke…
|
CWE-863
Incorrect Authorization
|
CVE-2020-14214
|
2024-11-21 14:02 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209626
|
5.4 |
MEDIUM
Network
|
zammad
|
zammad
|
In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data, split, or merge).
|
CWE-862
Missing Authorization
|
CVE-2020-14213
|
2024-11-21 14:02 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209627
|
8.8 |
HIGH
Network
|
ffmpeg
|
ffmpeg
|
FFmpeg through 4.3 has a heap-based buffer overflow in avio_get_str in libavformat/aviobuf.c because dnn_backend_native.c calls ff_dnn_load_model_native and a certain index check is omitted.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-14212
|
2024-11-21 14:02 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209628
|
6.1 |
MEDIUM
Network
|
monitorapp
|
web_application_firewall application_insight_web_application
|
Reflected Cross-Site Scripting (XSS) vulnerability in MONITORAPP WAF in which script can be executed when responding to Request URL information. It provides a function to response to Request URL info…
|
CWE-79
Cross-site Scripting
|
CVE-2020-14210
|
2024-11-21 14:02 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209629
|
6.5 |
MEDIUM
Network
|
satoshilabs
|
trezor_model_t_firmware trezor_one_firmware
|
BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to trick a user into making two signatures in certain cases, potentially leading t…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-14199
|
2024-11-21 14:02 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209630
|
8.1 |
HIGH
Network
|
fasterxml netapp debian oracle
|
jackson-databind steelstore_cloud_integrated_storage active_iq_unified_manager debian_linux agile_plm banking_digital_experience communications_instant_messaging_server communica…
|
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-14195
|
2024-11-21 14:02 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|