|
210151
|
8.1 |
HIGH
Network
|
python fedoraproject canonical
|
pillow fedora ubuntu_linux
|
In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-11538
|
2024-11-21 13:58 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210152
|
5.3 |
MEDIUM
Network
|
wolfssl
|
wolfssl
|
The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use a constant-time modular inverse when mapping to affine coordinates, aka a "projective coordinates leak."
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-11735
|
2024-11-21 13:58 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210153
|
7.5 |
HIGH
Network
|
mi
|
xiaomi_r3600_firmware
|
Xiaomi router R3600 ROM before 1.0.50 is affected by a sensitive information leakage caused by an insecure interface get_config_result without authentication
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-11961
|
2024-11-21 13:58 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210154
|
9.8 |
CRITICAL
Network
|
mi
|
xiaomi_r3600_firmware
|
Xiaomi router R3600 ROM before 1.0.50 is affected by a vulnerability when checking backup file in c_upload interface let attacker able to extract malicious file under any location in /tmp, lead to po…
|
NVD-CWE-noinfo
|
CVE-2020-11960
|
2024-11-21 13:58 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210155
|
7.5 |
HIGH
Network
|
mi
|
xiaomi_r3600_firmware
|
An unsafe configuration of nginx lead to information leak in Xiaomi router R3600 ROM before 1.0.50.
|
NVD-CWE-noinfo
|
CVE-2020-11959
|
2024-11-21 13:58 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210156
|
7.8 |
HIGH
Local
|
winmagic
|
securedoc
|
The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to write to arbitrary kernel memory addresses because the IOCTL dispatcher lacks pointer validation. Exploiting this …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-11520
|
2024-11-21 13:58 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210157
|
7.8 |
HIGH
Local
|
winmagic
|
securedoc
|
The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to read or write to physical disc sectors via a \\.\SecureDocDevice handle. Exploiting this vulnerability results in …
|
NVD-CWE-noinfo
|
CVE-2020-11519
|
2024-11-21 13:58 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210158
|
9.8 |
CRITICAL
Network
|
sophos
|
sfos
|
A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-11503
|
2024-11-21 13:58 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210159
|
4.3 |
MEDIUM
Adjacent
|
treck
|
tcp\/ip
|
The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-11914
|
2024-11-21 13:58 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210160
|
5.3 |
MEDIUM
Network
|
treck
|
tcp\/ip
|
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-11913
|
2024-11-21 13:58 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|