|
209931
|
4.3 |
MEDIUM
Adjacent
|
centreon
|
widget-host-monitoring centreon
|
Centreon before 19.10.7 exposes Session IDs in server responses.
|
CWE-200
Information Exposure
|
CVE-2020-10945
|
2024-11-21 13:56 |
2020-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209932
|
7.5 |
HIGH
Network
|
puma fedoraproject debian
|
puma fedora debian_linux
|
In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.
|
-
|
CVE-2020-11076
|
2024-11-21 13:56 |
2020-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209933
|
7.5 |
HIGH
Network
|
puma fedoraproject debian opensuse
|
puma fedora debian_linux leap
|
In Puma (RubyGem) before 4.3.5 and 3.12.6, a client could smuggle a request through a proxy, causing the proxy to send a response back to another unknown client. If the proxy uses persistent connecti…
|
-
|
CVE-2020-11077
|
2024-11-21 13:56 |
2020-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209934
|
6.8 |
MEDIUM
Network
|
httplib2_project fedoraproject debian
|
httplib2 fedora debian_linux
|
In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. T…
|
-
|
CVE-2020-11078
|
2024-11-21 13:56 |
2020-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209935
|
7.5 |
HIGH
Network
|
powerdns fedoraproject debian opensuse
|
recursor fedora debian_linux leap backports_sle
|
PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the DNS protocol has been found that allow malicious parties to use recu…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-10995
|
2024-11-21 13:56 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209936
|
5.3 |
MEDIUM
Network
|
dovecot
|
dovecot
|
In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart.
|
CWE-20
Improper Input Validation
|
CVE-2020-10967
|
2024-11-21 13:56 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209937
|
5.3 |
MEDIUM
Network
|
dovecot
|
dovecot
|
In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving …
|
CWE-416
Use After Free
|
CVE-2020-10958
|
2024-11-21 13:56 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209938
|
7.5 |
HIGH
Network
|
dovecot
|
dovecot
|
In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-10957
|
2024-11-21 13:56 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209939
|
8.8 |
HIGH
Network
|
typo3
|
typo3
|
In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that backend user settings (in $BE_USER->uc) are vulnerable to insecure deserialization. In combination with vulner…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-11067
|
2024-11-21 13:56 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209940
|
5.4 |
MEDIUM
Network
|
typo3
|
typo3
|
In TYPO3 CMS greater than or equal to 9.5.12 and less than 9.5.17, and greater than or equal to 10.2.0 and less than 10.4.2, it has been discovered that link tags generated by typolink functionality …
|
CWE-79
Cross-site Scripting
|
CVE-2020-11065
|
2024-11-21 13:56 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|