|
209021
|
4.3 |
MEDIUM
Network
|
field_test_project
|
field_test
|
The Field Test gem 0.2.0 through 0.3.2 for Ruby allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-16252
|
2024-11-21 14:07 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209022
|
6.1 |
MEDIUM
Network
|
extremenetworks
|
extreme_management_center
|
Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in a GET request, aka CFD-4887.
|
CWE-79
Cross-site Scripting
|
CVE-2020-16847
|
2024-11-21 14:07 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209023
|
5.9 |
MEDIUM
Network
|
amazon
|
firecracker
|
In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. This can result in a denial of service on the microVM when it is configured wit…
|
NVD-CWE-noinfo
|
CVE-2020-16843
|
2024-11-21 14:07 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209024
|
9.1 |
CRITICAL
Network
|
kee
|
keepassrpc
|
The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 is missing validation for a client-provided parameter, which allows remote attackers to read and modify data in the KeePass database vi…
|
CWE-20
Improper Input Validation
|
CVE-2020-16272
|
2024-11-21 14:07 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209025
|
9.1 |
CRITICAL
Network
|
kee
|
keepassrpc
|
The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 generates insufficiently random numbers, which allows remote attackers to read and modify data in the KeePass database via a WebSocket …
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-16271
|
2024-11-21 14:07 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209026
|
5.5 |
MEDIUM
Local
|
radare fedoraproject
|
radare2 fedora
|
radare2 4.5.0 misparses DWARF information in executable files, causing a segmentation fault in parse_typedef in type_dwarf.c via a malformed DW_AT_name in the .debug_info section.
|
NVD-CWE-noinfo
|
CVE-2020-16269
|
2024-11-21 14:07 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209027
|
8.8 |
HIGH
Network
|
mozilla
|
thunderbird
|
During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. This vulnerability affects Thunderbird < 78.7.
|
CWE-77
Command Injection
|
CVE-2020-15685
|
2024-11-21 14:06 |
2022-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209028
|
7.6 |
HIGH
Network
|
mozilla
|
vpn
|
An OAuth session fixation vulnerability existed in the VPN login flow, where an attacker could craft a custom login URL, convince a VPN user to login via that URL, and obtain authenticated access as …
|
CWE-384
Session Fixation
|
CVE-2020-15679
|
2024-11-21 14:06 |
2022-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209029
|
5.3 |
MEDIUM
Network
|
fedoraproject
|
supybot-fedora
|
supybot-fedora implements the command 'refresh', that refreshes the cache of all users from FAS. This takes quite a while to run, and zodbot stops responding to requests during this time.
|
NVD-CWE-noinfo
|
CVE-2020-15853
|
2024-11-21 14:06 |
2022-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209030
|
6.1 |
MEDIUM
Network
|
redhat
|
bodhi
|
Two cross-site scripting vulnerabilities were fixed in Bodhi 5.6.1.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15855
|
2024-11-21 14:06 |
2022-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|