|
209631
|
10.0 |
CRITICAL
Network
|
hms-networks
|
ecatcher
|
HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-14498
|
2024-11-21 14:03 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209632
|
9.8 |
CRITICAL
Network
|
softing
|
opc
|
Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely exe…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-14524
|
2024-11-21 14:03 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209633
|
7.5 |
HIGH
Network
|
softing
|
opc
|
Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to uncontrolled resource consumption, which may allow an attacker to cause a…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-14522
|
2024-11-21 14:03 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209634
|
7.5 |
HIGH
Network
|
secomea
|
gatemanager_8250_firmware
|
GateManager versions prior to 9.2c, The affected product uses a weak hash type, which may allow an attacker to view user passwords.
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2020-14512
|
2024-11-21 14:03 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209635
|
9.8 |
CRITICAL
Network
|
secomea
|
gatemanager_8250_firmware
|
GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for telnet, allowing an unprivileged attacker to execute commands as root.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-14510
|
2024-11-21 14:03 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209636
|
9.8 |
CRITICAL
Network
|
secomea
|
gatemanager_8250_firmware
|
GateManager versions prior to 9.2c, The affected product is vulnerable to an off-by-one error, which may allow an attacker to remotely execute arbitrary code or cause a denial-of-service condition.
|
CWE-193
Off-by-one Error
|
CVE-2020-14508
|
2024-11-21 14:03 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209637
|
9.8 |
CRITICAL
Network
|
secomea
|
gatemanager_8250_firmware
|
Secomea GateManager all versions prior to 9.2c, An attacker can send a negative value and overwrite arbitrary data.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-14500
|
2024-11-21 14:03 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209638
|
6.0 |
MEDIUM
Local
|
tuxfamily fedoraproject canonical
|
chrony fedora ubuntu_linux
|
A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when…
|
CWE-59
Link Following
|
CVE-2020-14367
|
2024-11-21 14:03 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209639
|
7.3 |
HIGH
Local
|
postgresql debian opensuse canonical
|
postgresql debian_linux leap ubuntu_linux
|
It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into exe…
|
CWE-426
Untrusted Search Path
|
CVE-2020-14350
|
2024-11-21 14:03 |
2020-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209640
|
7.1 |
HIGH
Network
|
postgresql opensuse
|
postgresql leap
|
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in …
|
CWE-89 CWE-427
SQL Injection Uncontrolled Search Path Element
|
CVE-2020-14349
|
2024-11-21 14:03 |
2020-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|