|
196931
|
9.8 |
CRITICAL
Network
|
linuxfoundation
|
the_update_framework
|
TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-6174
|
2024-11-21 14:35 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196932
|
7.5 |
HIGH
Network
|
minisnmpd_project
|
minisnmpd
|
A stack buffer overflow vulnerability exists in the way MiniSNMPD version 1.4 handles multiple connections. A specially timed sequence of SNMP connections can trigger a stack overflow, resulting in a…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6060
|
2024-11-21 14:35 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196933
|
8.2 |
HIGH
Network
|
minisnmpd_project
|
minisnmpd
|
An exploitable out of bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP request can trigger an out of bounds memory read which c…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-6059
|
2024-11-21 14:35 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196934
|
9.1 |
CRITICAL
Network
|
minisnmpd_project
|
minisnmpd
|
An exploitable out-of-bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP request can trigger an out-of-bounds memory read, which …
|
CWE-125
Out-of-bounds Read
|
CVE-2020-6058
|
2024-11-21 14:35 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196935
|
5.3 |
MEDIUM
Network
|
linuxfoundation
|
the_update_framework
|
TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-6173
|
2024-11-21 14:35 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196936
|
4.3 |
MEDIUM
Network
|
sap
|
basis
|
Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) does not perform sufficient authorization checks leading to the reading of sensiti…
|
CWE-863
Incorrect Authorization
|
CVE-2020-6307
|
2024-11-21 14:35 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196937
|
2.7 |
LOW
Network
|
sap
|
leasing
|
Missing authorization check in a transaction within SAP Leasing (update provided in SAP_APPL 6.18, EA-APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16 and 6.17).
|
CWE-862
Missing Authorization
|
CVE-2020-6306
|
2024-11-21 14:35 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196938
|
6.1 |
MEDIUM
Network
|
sap
|
process_integration
|
PI Rest Adapter of SAP Process Integration (update provided in SAP_XIAF 7.31, 7.40, 7.50) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-6305
|
2024-11-21 14:35 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196939
|
5.4 |
MEDIUM
Network
|
sap
|
disclosure_management
|
SAP Disclosure Management, before version 10.1, does not validate user input properly in specific use cases leading to Cross-Site Scripting.
|
CWE-79
Cross-site Scripting
|
CVE-2020-6303
|
2024-11-21 14:35 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196940
|
8.8 |
HIGH
Network
|
google opensuse fedoraproject redhat debian
|
chrome leap backports_sle fedora enterprise_linux_desktop enterprise_linux_workstation debian_linux
|
Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2020-6377
|
2024-11-21 14:35 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|