|
196321
|
9.8 |
CRITICAL
Network
|
hp
|
linuxki
|
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
|
NVD-CWE-noinfo
|
CVE-2020-7209
|
2024-11-21 14:36 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196322
|
6.1 |
MEDIUM
Network
|
hp
|
linuxki
|
LinuxKI v6.0-1 and earlier is vulnerable to an XSS which is resolved in release 6.0-2.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7208
|
2024-11-21 14:36 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196323
|
6.2 |
MEDIUM
Network
|
digi
|
connectport_lts_32_mei_bios connectport_lts_32_mei_firmware
|
Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2. Multiple cross-site scripting vulnerabilities exist that could allow an attacker to cause …
|
CWE-79
Cross-site Scripting
|
CVE-2020-6973
|
2024-11-21 14:36 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196324
|
4.9 |
MEDIUM
Network
|
digi
|
connectport_lts_32_mei_bios connectport_lts_32_mei_firmware
|
Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2. Successful exploitation of this vulnerability could allow an attacker to upload a maliciou…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-6975
|
2024-11-21 14:36 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196325
|
7.5 |
HIGH
Network
|
dovecot fedoraproject
|
dovecot fedora
|
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login in…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-7046
|
2024-11-21 14:36 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196326
|
7.5 |
HIGH
Network
|
opensuse
|
wicked
|
An ni_dhcp4_fsm_process_dhcp4_packet memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets with a different client-id.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-7217
|
2024-11-21 14:36 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196327
|
9.1 |
CRITICAL
Network
|
php tenable oracle opensuse debian
|
php tenable.sc communications_diameter_signaling_router leap debian_linux
|
When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause functi…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-7060
|
2024-11-21 14:36 |
2020-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196328
|
9.1 |
CRITICAL
Network
|
php tenable oracle opensuse debian
|
php tenable.sc communications_diameter_signaling_router leap debian_linux
|
When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-7059
|
2024-11-21 14:36 |
2020-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196329
|
9.8 |
CRITICAL
Network
|
bosch
|
bosch_video_management_system_mobile_video_service divar_ip_3000_firmware divar_ip_7000_firmware
|
Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch BVMS versions 10.0 …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-6770
|
2024-11-21 14:36 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196330
|
7.5 |
HIGH
Network
|
bosch
|
video_management_system_viewer video_management_system
|
A path traversal vulnerability in the Bosch Video Management System (BVMS) NoTouch deployment allows an unauthenticated remote attacker to read arbitrary files from the Central Server. This affects B…
|
CWE-22
Path Traversal
|
CVE-2020-6768
|
2024-11-21 14:36 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|