|
198501
|
5.5 |
MEDIUM
Local
|
taidii
|
diibear
|
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to view private chat messages and media files via logcat because of excessive logging.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-35456
|
2024-11-21 14:27 |
2021-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198502
|
7.8 |
HIGH
Local
|
taidii
|
diibear
|
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from Shared Preferences and the SQLite database because of insecure data storage.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-35455
|
2024-11-21 14:27 |
2021-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198503
|
6.8 |
MEDIUM
Physics
|
taidii
|
diibear
|
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from an Android backup because of insecure application configuration.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-35454
|
2024-11-21 14:27 |
2021-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198504
|
9.8 |
CRITICAL
Network
|
domainmod
|
domainmod
|
DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed password and old sessions in any other browser or …
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-35358
|
2024-11-21 14:27 |
2021-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198505
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).
|
CWE-863
Incorrect Authorization
|
CVE-2020-35682
|
2024-11-21 14:27 |
2021-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198506
|
6.5 |
MEDIUM
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external attackers to force device reboots by sending concurrent connections, aka a den…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-35233
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198507
|
8.8 |
HIGH
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue that allows an attacker to bypass access controls and obtain full control of th…
|
CWE-287
Improper Authentication
|
CVE-2020-35231
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198508
|
6.8 |
MEDIUM
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
Multiple integer overflow parameters were found in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices. Most of the integer parameters sent through the web server can be abuse…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-35230
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198509
|
8.8 |
HIGH
Adjacent
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can be reused until a new token is generated, which all…
|
CWE-384
Session Fixation
|
CVE-2020-35229
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198510
|
4.8 |
MEDIUM
Network
|
netgear
|
gs116e_firmware jgs516pe_firmware
|
A cross-site scripting (XSS) vulnerability in the administration web panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote attackers to inject arbitrary web script or HTML via the langua…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35228
|
2024-11-21 14:27 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|