|
211481
|
7.5 |
HIGH
Network
|
citrix
|
gateway_firmware
|
Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests. NOTE: Citrix disputes the reported behavior as not a security issue. Citrix ADC only caches HTTP/1.1 traffic f…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-10111
|
2024-11-21 13:54 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211482
|
5.3 |
MEDIUM
Network
|
citrix
|
gateway_firmware
|
Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There is no sensitive information disclosure through the cache head…
|
NVD-CWE-noinfo
|
CVE-2020-10110
|
2024-11-21 13:54 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211483
|
7.5 |
HIGH
Network
|
eset
|
smart_security nod32_antivirus mobile_security smart_tv_security internet_security cyber_security
|
ESET Archive Support Module before 1294 allows virus-detection bypass via crafted RAR Compression Information in an archive. This affects versions before 1294 of Smart Security Premium, Internet Secu…
|
CWE-436
Interpretation Conflict
|
CVE-2020-10193
|
2024-11-21 13:54 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211484
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_desktop_central
|
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfSer…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-10189
|
2024-11-21 13:54 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211485
|
9.8 |
CRITICAL
Network
|
netkit_telnet_project fedoraproject debian arista oracle juniper
|
netkit_telnet fedora debian_linux eos communications_performance_intelligence_center junos
|
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-10188
|
2024-11-21 13:54 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211486
|
8.6 |
HIGH
Network
|
yubico
|
yubikey_one_time_password_validation_server
|
The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP v…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2020-10185
|
2024-11-21 13:54 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211487
|
7.5 |
HIGH
Network
|
yubico
|
yubikey_one_time_password_validation_server
|
The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remote attackers to cause a denial of service, aka SQL injection. NOTE: this issue …
|
CWE-89
SQL Injection
|
CVE-2020-10184
|
2024-11-21 13:54 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211488
|
9.8 |
CRITICAL
Network
|
eset
|
nod32_antivirus smart_security mobile_security smart_tv_security cyber_security
|
The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antiviru…
|
CWE-436
Interpretation Conflict
|
CVE-2020-10180
|
2024-11-21 13:54 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211489
|
7.0 |
HIGH
Local
|
timeshift_project fedoraproject canonical
|
timeshift fedora ubuntu_linux
|
init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the predictable location /tmp/timeshift. It follows symlinks in this location or uses…
|
CWE-362 CWE-59
Race Condition Link Following
|
CVE-2020-10174
|
2024-11-21 13:54 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211490
|
8.8 |
HIGH
Network
|
comtrend
|
vr-3033_firmware
|
Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metac…
|
CWE-78
OS Command
|
CVE-2020-10173
|
2024-11-21 13:54 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|