|
210121
|
9.1 |
CRITICAL
Network
|
linux4sam
|
at91bootstrap
|
AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component. This can be exploited to disclose thes…
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2020-11684
|
2024-11-21 13:58 |
2020-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210122
|
6.8 |
MEDIUM
Physics
|
linux4sam
|
at91bootstrap
|
A timing side channel was discovered in AT91bootstrap before 3.9.2. It can be exploited by attackers with physical access to forge CMAC values and subsequently boot arbitrary code on an affected syst…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-11683
|
2024-11-21 13:58 |
2020-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210123
|
8.1 |
HIGH
Network
|
foxitsoftware
|
phantompdf reader
|
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-11493
|
2024-11-21 13:58 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210124
|
7.5 |
HIGH
Network
|
chadhaajay
|
phpkb
|
An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unauthenticated attacker to disclose local files on ho…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-11579
|
2024-11-21 13:58 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210125
|
7.8 |
HIGH
Local
|
thomsonstb philips
|
tht741fta_firmware dtr3502bfta_dvb-t2_firmware
|
THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes have their TELNET service hardcoded to start on boot, which allows an attacker on the local network to achieve root access v…
|
NVD-CWE-noinfo
|
CVE-2020-11618
|
2024-11-21 13:58 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210126
|
5.9 |
MEDIUM
Network
|
thomsonstb philips
|
tht741fta_firmware dtr3502bfta_dvb-t2_firmware
|
The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to mo…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-11617
|
2024-11-21 13:58 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210127
|
7.5 |
HIGH
Network
|
mitel
|
micollab_audio\ _web_\&_video_conferencing
|
An Authentication Bypass vulnerability in the Published Area of the web conferencing component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an unauthenticated attacker to gai…
|
NVD-CWE-noinfo
|
CVE-2020-11797
|
2024-11-21 13:58 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210128
|
7.5 |
HIGH
Network
|
woocommerce
|
nab_transact
|
An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrar…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-11497
|
2024-11-21 13:58 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210129
|
7.5 |
HIGH
Network
|
microfocus
|
arcsight_management_center
|
Denial of service vulnerability on Micro Focus ArcSight Management Center. Affecting all versions prior to version 2.9.5. The vulnerability could cause the server to become unavailable, causing a den…
|
NVD-CWE-noinfo
|
CVE-2020-11848
|
2024-11-21 13:58 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210130
|
6.7 |
MEDIUM
Local
|
spirent
|
avalanche testcenter
|
An issue was discovered on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already has access to an SSH restricted shell, can achieve root access via shell metac…
|
CWE-78
OS Command
|
CVE-2020-11733
|
2024-11-21 13:58 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|