|
208611
|
7.5 |
HIGH
Network
|
huawei
|
nip6800_firmware secospace_usg6600_firmware usg9500_firmware
|
NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an out-of-bounds read vulnerability. An unauthenticated attacker crafts malformed me…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-1873
|
2024-11-21 14:11 |
2020-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208612
|
7.5 |
HIGH
Network
|
huawei
|
nip6800_firmware secospace_usg6600_firmware usg9500_firmware
|
NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an access control bypass vulnerability. Attackers that can access to the internal ne…
|
NVD-CWE-noinfo
|
CVE-2020-1860
|
2024-11-21 14:11 |
2020-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208613
|
5.5 |
MEDIUM
Local
|
huawei
|
nip6800_firmware secospace_usg6600_firmware usg9500_firmware
|
NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid pointer access vulnerability. The software system access an invalid pointer wh…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2020-1875
|
2024-11-21 14:11 |
2020-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208614
|
4.4 |
MEDIUM
Local
|
huawei
|
cloudengine_12800_firmware
|
CloudEngine 12800 with versions of V200R001C00SPC600,V200R001C00SPC700,V200R002C01,V200R002C50SPC800,V200R002C50SPC800PWE,V200R003C00SPC810,V200R003C00SPC810PWE,V200R005C00SPC600,V200R005C00SPC800,V2…
|
NVD-CWE-noinfo
|
CVE-2020-1861
|
2024-11-21 14:11 |
2020-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208615
|
7.8 |
HIGH
Local
|
huawei
|
pcmanager
|
PCManager with versions earlier than 10.0.5.51 have a privilege escalation vulnerability in Huawei PCManager products. An authenticated, local attacker can perform specific operation to exploit this …
|
NVD-CWE-noinfo
|
CVE-2020-1844
|
2024-11-21 14:11 |
2020-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208616
|
5.5 |
MEDIUM
Local
|
huawei
|
honor_v10_firmware
|
Honor V10 smartphones with versions earlier than BKL-AL20 10.0.0.156(C00E156R2P4) and versions earlier than BKL-L09 10.0.0.146(C432E4R1P4) have an out of bounds write vulnerability. The software writ…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-1792
|
2024-11-21 14:11 |
2020-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208617
|
8.8 |
HIGH
Network
|
apache
|
kylin
|
Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.
|
CWE-89
SQL Injection
|
CVE-2020-1937
|
2024-11-21 14:11 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208618
|
9.8 |
CRITICAL
Network
|
apache fedoraproject oracle debian opensuse blackberry netapp
|
tomcat geode fedora transportation_management hospitality_guest_access agile_plm instantis_enterprisetrack mysql_enterprise_monitor health_sciences_empirica_signal communic…
|
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar H…
|
NVD-CWE-Other
|
CVE-2020-1938
|
2024-11-21 14:11 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208619
|
4.8 |
MEDIUM
Network
|
apache debian canonical opensuse netapp oracle
|
tomcat debian_linux ubuntu_linux leap oncommand_system_manager data_availability_services transportation_management hospitality_guest_access retail_order_broker agile_produ…
|
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as va…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-1935
|
2024-11-21 14:11 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208620
|
6.8 |
MEDIUM
Physics
|
huawei
|
hege-560_firmware osca-550_firmware osca-550a_firmware osca-550ax_firmware osca-550x_firmware
|
Huawei HEGE-560 version 1.0.1.20(SP2); OSCA-550 and OSCA-550A version 1.0.0.71(SP1); and OSCA-550AX and OSCA-550X version 1.0.0.71(SP2) have an insufficient authentication vulnerability. An attacker …
|
CWE-287
Improper Authentication
|
CVE-2020-1842
|
2024-11-21 14:11 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|