|
210281
|
7.5 |
HIGH
Network
|
zoom
|
meetings
|
airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption. NOTE: the vendor states that this IV is used only within unreachable…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-11877
|
2024-11-21 13:58 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210282
|
7.5 |
HIGH
Network
|
zoom
|
meetings
|
airhost.exe in Zoom Client for Meetings 4.6.11 uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of an OpenSSL EVP AES-256 CBC context. NOTE: the vendor states that this initializa…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-11876
|
2024-11-21 13:58 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210283
|
7.8 |
HIGH
Local
|
google
|
android
|
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10.0 (MTK chipsets) software. The MTK kernel does not properly implement exception handling, allowing an attacker to ga…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-11875
|
2024-11-21 13:58 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210284
|
7.5 |
HIGH
Network
|
google
|
android
|
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. Attackers can bypass Factory Reset Protection (FRP). The LG ID is LVE-SMP-200004 (March 2020).
|
NVD-CWE-noinfo
|
CVE-2020-11874
|
2024-11-21 13:58 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210285
|
9.8 |
CRITICAL
Network
|
google
|
android
|
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A stack-based buffer overflow in the logging tool could allow an attacker to gain privileges. The LG ID…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-11873
|
2024-11-21 13:58 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210286
|
8.8 |
HIGH
Network
|
wpewebkit webkitgtk canonical fedoraproject opensuse
|
wpe_webkit webkitgtk ubuntu_linux fedora leap
|
A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute arbitrary code or cause a denial of service (memo…
|
CWE-416
Use After Free
|
CVE-2020-11793
|
2024-11-21 13:58 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210287
|
7.5 |
HIGH
Network
|
bluetrace
|
opentrace
|
The Cloud Functions subsystem in OpenTrace 1.0 might allow fabrication attacks by making billions of TempID requests before an AES-256-GCM key rotation occurs.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-11872
|
2024-11-21 13:58 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210288
|
7.5 |
HIGH
Network
|
ntp redhat netapp debian opensuse
|
ntp enterprise_linux clustered_data_ontap virtual_storage_console data_ontap vasa_provider_for_clustered_data_ontap solidfire hci_management_node hci_storage_node_firmware …
|
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissi…
|
CWE-346
Origin Validation Error
|
CVE-2020-11868
|
2024-11-21 13:58 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210289
|
7.5 |
HIGH
Network
|
appinghouse
|
memono
|
Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker …
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-11826
|
2024-11-21 13:58 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210290
|
8.8 |
HIGH
Network
|
dolibarr
|
dolibarr_erp\/crm
|
In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be va…
|
CWE-352
Origin Validation Error
|
CVE-2020-11825
|
2024-11-21 13:58 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|