|
208291
|
8.8 |
HIGH
Network
|
maxum
|
rumpus
|
Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site request forgery (CSRF). If an authenticated user visits a malicious page, unintended actions could be performed in the web application as the …
|
CWE-352
Origin Validation Error
|
CVE-2020-27574
|
2024-11-21 14:21 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208292
|
7.5 |
HIGH
Local
|
gnu redhat fedoraproject netapp
|
grub2 enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux enterprise_linux_server_tus enterprise_linux_server_eus fedora ontap_select_deploy_administration_…
|
A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity…
|
NVD-CWE-Other
|
CVE-2020-27779
|
2024-11-21 14:21 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208293
|
6.7 |
MEDIUM
Local
|
gnu redhat fedoraproject netapp
|
grub2 enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux enterprise_linux_server_tus enterprise_linux_server_eus fedora ontap_select_deploy_administration_…
|
A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line into their corresponding variable contents, using a 1kB stack buffer for temporar…
|
-
|
CVE-2020-27749
|
2024-11-21 14:21 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208294
|
5.5 |
MEDIUM
Local
|
gnu netapp oracle debian
|
glibc ontap_select_deploy_administration_utility a250_firmware 500f_firmware h410c_firmware h300s_firmware h500s_firmware h700s_firmware h300e_firmware h500e_firmware h7…
|
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails t…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-27618
|
2024-11-21 14:21 |
2021-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208295
|
7.5 |
HIGH
Network
|
restify-paginate_project
|
restify-paginate
|
The restify-paginate package 0.0.5 for Node.js allows remote attackers to cause a Denial-of-Service by omitting the HTTP Host header. A Restify-based web service would crash with an uncaught exceptio…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-27543
|
2024-11-21 14:21 |
2021-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208296
|
7.5 |
HIGH
Network
|
redhat
|
jboss_fuse openshift_application_runtimes undertow
|
A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a …
|
-
|
CVE-2020-27782
|
2024-11-21 14:21 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208297
|
5.5 |
MEDIUM
Local
|
libxls_project
|
libxls
|
An issue was discovered in libxls before and including 1.6.1 when reading Microsoft Excel files. A NULL pointer dereference vulnerability exists when parsing XLS cells in libxls/xls2csv.c:199. It cou…
|
-
|
CVE-2020-27819
|
2024-11-21 14:21 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208298
|
3.3 |
LOW
Local
|
imagemagick debian
|
imagemagick debian_linux
|
In ImageMagick, there is an outside the range of representable values of type 'unsigned int' at MagickCore/quantum-private.h. This flaw affects ImageMagick versions prior to 7.0.9-0.
|
-
|
CVE-2020-27768
|
2024-11-21 14:21 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208299
|
8.8 |
HIGH
Network
|
solarwinds
|
network_performance_monitor
|
This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Performance Monitor 2020 HF1, NPM: 2020.2. Authentication is required to exploit this…
|
-
|
CVE-2020-27869
|
2024-11-21 14:21 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208300
|
9.8 |
CRITICAL
Network
|
qognify
|
ocularis
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Qognify Ocularis 5.9.0.395. Authentication is not required to exploit this vulnerability. The specifi…
|
-
|
CVE-2020-27868
|
2024-11-21 14:21 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|