|
209911
|
9.8 |
CRITICAL
Network
|
opmantek
|
open-audit
|
An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections.
|
CWE-89
SQL Injection
|
CVE-2020-11942
|
2024-11-21 13:58 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209912
|
8.8 |
HIGH
Adjacent
|
cerner
|
medico
|
Cerner medico 26.00 has a Local Buffer Overflow (issue 3 of 3).
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-11677
|
2024-11-21 13:58 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209913
|
8.8 |
HIGH
Adjacent
|
cerner
|
medico
|
Cerner medico 26.00 has a Local Buffer Overflow (issue 2 of 3).
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-11676
|
2024-11-21 13:58 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209914
|
8.8 |
HIGH
Adjacent
|
cerner
|
medico
|
Cerner medico 26.00 has a Local Buffer Overflow (issue 1 of 3).
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-11675
|
2024-11-21 13:58 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209915
|
8.8 |
HIGH
Adjacent
|
cerner
|
medico
|
Cerner medico 26.00 allows variable reuse, possibly causing data corruption.
|
NVD-CWE-noinfo
|
CVE-2020-11674
|
2024-11-21 13:58 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209916
|
7.0 |
HIGH
Local
|
linux canonical debian fedoraproject netapp
|
linux_kernel ubuntu_linux debian_linux fedora cloud_backup element_software steelstore_cloud_integrated_storage solidfire hci_management_node active_iq_unified_manager s…
|
In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails…
|
CWE-362
Race Condition
|
CVE-2020-11884
|
2024-11-21 13:58 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209917
|
3.3 |
LOW
Local
|
qemu
|
qemu
|
An integer overflow was found in QEMU 4.0.1 through 4.2.0 in the way it implemented ATI VGA emulation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati-2d.c while handling MMIO write op…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-11869
|
2024-11-21 13:58 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209918
|
8.8 |
HIGH
Network
|
opmantek
|
open-audit
|
An issue was discovered in Open-AudIT 3.2.2. There is OS Command injection in Discovery.
|
CWE-78
OS Command
|
CVE-2020-11941
|
2024-11-21 13:58 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209919
|
6.1 |
MEDIUM
Network
|
rukovoditel
|
rukovoditel
|
In Rukovoditel 2.5.2, there is a stored XSS vulnerability on the application structure --> user access groups page. Thus, an attacker can inject malicious script to steal all users' valuable data.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11822
|
2024-11-21 13:58 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209920
|
5.3 |
MEDIUM
Network
|
rukovoditel
|
rukovoditel
|
In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hashing. Thus, an attacker can easily apply brute force on them.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-11821
|
2024-11-21 13:58 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|