|
198971
|
7.1 |
HIGH
Local
|
apple
|
iphone_os watchos icloud tvos ipados itunes macos
|
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iCloud for Windows 11.4, iOS 14.0 and iPadOS 14.0, watchOS 7.0, tvOS 14.0, iCloud for Windows 7.21, iTunes f…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-36521
|
2024-11-21 14:29 |
2022-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198972
|
8.1 |
HIGH
Network
|
hapijs
|
hoek
|
hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-36604
|
2024-11-21 14:29 |
2022-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198973
|
6.1 |
MEDIUM
Physics
|
huawei
|
576up005_hota-cm-h-shark-bd_firmware 577hota-cm-h-shark-bd_firmware 581up-hota-cm-h-shark-bd_firmware 586-hota-cm-h-shark-bd_firmware 588-hota-cm-h-shark-bd_firmware 606-hota-cm-h-shar…
|
There is an out-of-bounds read and write vulnerability in some headset products. An unauthenticated attacker gets the device physically and crafts malformed message with specific parameter and sends …
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-36602
|
2024-11-21 14:29 |
2022-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198974
|
7.5 |
HIGH
Network
|
huawei
|
magic_ui emui
|
Out-of-bounds write vulnerability in the kernel modules. Successful exploitation of this vulnerability may cause a panic reboot.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-36601
|
2024-11-21 14:29 |
2022-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198975
|
7.5 |
HIGH
Network
|
huawei
|
magic_ui emui
|
Out-of-bounds write vulnerability in the power consumption module. Successful exploitation of this vulnerability may cause the system to restart.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-36600
|
2024-11-21 14:29 |
2022-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198976
|
6.5 |
MEDIUM
Local
|
hoyoverse
|
mhyprot2
|
The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calls, allowing local, unprivileged users to execute arbitrary…
|
NVD-CWE-noinfo
|
CVE-2020-36603
|
2024-11-21 14:29 |
2022-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198977
|
9.8 |
CRITICAL
Network
|
omniauth
|
omniauth
|
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2020-36599
|
2024-11-21 14:29 |
2022-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198978
|
5.4 |
MEDIUM
Network
|
atlassian
|
confluence_server confluence_data_center
|
The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to…
|
CWE-79
Cross-site Scripting
|
CVE-2020-36290
|
2024-11-21 14:29 |
2022-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198979
|
5.1 |
MEDIUM
Local
|
linux
|
linux_kernel
|
A race condition in the Linux kernel before 5.5.7 involving VT_RESIZEX could lead to a NULL pointer dereference and general protection fault.
|
CWE-362 CWE-476
Race Condition NULL Pointer Dereference
|
CVE-2020-36558
|
2024-11-21 14:29 |
2022-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198980
|
5.1 |
MEDIUM
Local
|
linux
|
linux_kernel
|
A race condition in the Linux kernel before 5.6.2 between the VT_DISALLOCATE ioctl and closing/opening of ttys could lead to a use-after-free.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2020-36557
|
2024-11-21 14:29 |
2022-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|