|
199431
|
3.9 |
LOW
Local
|
qemu debian
|
qemu debian_linux
|
ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-29443
|
2024-11-21 14:24 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199432
|
6.5 |
MEDIUM
Network
|
atlassian
|
confluence_server confluence_data_center
|
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload featu…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-29450
|
2024-11-21 14:24 |
2021-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199433
|
5.3 |
MEDIUM
Network
|
atlassian
|
crucible fisheye
|
Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. The affected ver…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-29446
|
2024-11-21 14:24 |
2021-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199434
|
8.7 |
HIGH
Network
|
dell
|
emc_avamar_server emc_integrated_data_protection_appliance
|
Dell EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a Path Traversal Vulnerability in PDM. A remote user could potentially exploit this vulnerability, to gain unauthorized write access to the …
|
CWE-22
Path Traversal
|
CVE-2020-29494
|
2024-11-21 14:24 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199435
|
5.4 |
MEDIUM
Network
|
simplcommerce
|
simplcommerce
|
SimplCommerce 1.0.0-rc uses the Bootbox.js library, which allows creation of programmatic dialog boxes using Bootstrap modals. The Bootbox.js library intentionally does not perform any sanitization o…
|
CWE-79
Cross-site Scripting
|
CVE-2020-29587
|
2024-11-21 14:24 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199436
|
10.0 |
CRITICAL
Network
|
dell
|
emc_avamar_server emc_integrated_data_protection_appliance
|
DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, l…
|
CWE-78
OS Command
|
CVE-2020-29495
|
2024-11-21 14:24 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199437
|
9.8 |
CRITICAL
Network
|
dell
|
emc_avamar_server emc_integrated_data_protection_appliance
|
DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading t…
|
CWE-89
SQL Injection
|
CVE-2020-29493
|
2024-11-21 14:24 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199438
|
6.7 |
MEDIUM
Local
|
dell
|
emc_powerstore_firmware
|
Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit th…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-29502
|
2024-11-21 14:24 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199439
|
6.7 |
MEDIUM
Local
|
dell
|
emc_powerstore_firmware
|
Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore X & T environments. A locally authenticated attacker could potentially exploit th…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-29501
|
2024-11-21 14:24 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199440
|
6.7 |
MEDIUM
Local
|
dell
|
emc_powerstore_firmware
|
Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore T environments. A locally authenticated attacker could potentially exploit this v…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-29500
|
2024-11-21 14:24 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|