|
208301
|
8.2 |
HIGH
Network
|
ti
|
z-stack
|
The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Write Attributes No Response message. It crashes in zclParseInWriteCmd() and …
|
NVD-CWE-noinfo
|
CVE-2020-27890
|
2024-11-21 14:21 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208302
|
7.5 |
HIGH
Network
|
ui
|
unifi_meshing_access_point_firmware unifi_controller_firmware
|
An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices. Cached credentials are not erased from an access point returning wirelessly f…
|
CWE-459 CWE-522
Incomplete Cleanup Insufficiently Protected Credentials
|
CVE-2020-27888
|
2024-11-21 14:21 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208303
|
9.8 |
CRITICAL
Network
|
wire
|
wire_secure_messenger wire_-_audio\ _video\ _and_signaling wire
|
Wire before 2020-10-16 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a format string. This affects Wire AVS (Audio, Video, and Signal…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2020-27853
|
2024-11-21 14:21 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208304
|
9.8 |
CRITICAL
Network
|
pam_tacplus_project
|
pam_tacplus
|
libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to use of a non-random/predictable session_id.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-27743
|
2024-11-21 14:21 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208305
|
9.8 |
CRITICAL
Network
|
joyent omniosce illumos
|
smartos omnios illumos
|
An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022. There is a buffer overflow in parse_user_name in lib/lib…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-27678
|
2024-11-21 14:21 |
2020-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208306
|
5.4 |
MEDIUM
Network
|
yourls
|
yourls
|
Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload i…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27388
|
2024-11-21 14:21 |
2020-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208307
|
4.7 |
MEDIUM
Local
|
linux fedoraproject debian
|
linux_kernel fedora debian_linux
|
An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/xen/events/events_base.c allows event-channel removal during the event-handling loop (a race condit…
|
CWE-362 CWE-476 CWE-416
Race Condition NULL Pointer Dereference Use After Free
|
CVE-2020-27675
|
2024-11-21 14:21 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208308
|
5.3 |
MEDIUM
Local
|
xen fedoraproject debian
|
xen fedora debian_linux
|
An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-27674
|
2024-11-21 14:21 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208309
|
5.5 |
MEDIUM
Local
|
linux debian opensuse xen
|
linux_kernel debian_linux leap xen
|
An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a denial of service (host OS hang) via a high rate of events to dom0, aka CID-e995…
|
NVD-CWE-noinfo
|
CVE-2020-27673
|
2024-11-21 14:21 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208310
|
7.0 |
HIGH
Local
|
xen fedoraproject opensuse debian
|
xen fedora leap debian_linux
|
An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial of service, achieve data corruption, or possibly gain privileges by exploiting a race condition tha…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2020-27672
|
2024-11-21 14:21 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|