|
208311
|
6.7 |
MEDIUM
Local
|
cisco
|
identity_services_engine
|
A vulnerability in the Microsoft Active Directory integration of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to elevate privileges on an affected device. To expl…
|
CWE-269
Improper Privilege Management
|
CVE-2020-27122
|
2024-11-21 14:20 |
2020-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208312
|
6.5 |
MEDIUM
Network
|
cisco
|
unified_communications_manager_im_and_presence_service
|
A vulnerability in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) Software could allow an authenticated, remote attacker to cause the Cisco XCP Authentication Se…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-27121
|
2024-11-21 14:20 |
2020-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208313
|
7.5 |
HIGH
Network
|
lightbend
|
play_framework
|
An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2. The body parsing of HTTP requests eagerly parses a payload given a Content-Type header. A deep JSON structure sent to a vali…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-27196
|
2024-11-21 14:20 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208314
|
7.5 |
HIGH
Network
|
lightbend
|
play_framework
|
In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents.
|
CWE-674
Uncontrolled Recursion
|
CVE-2020-26883
|
2024-11-21 14:20 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208315
|
7.5 |
HIGH
Network
|
lightbend
|
play_framework
|
In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input.
|
CWE-674
Uncontrolled Recursion
|
CVE-2020-26882
|
2024-11-21 14:20 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208316
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper interaction between a resampler and edge trigg…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-27152
|
2024-11-21 14:20 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208317
|
9.8 |
CRITICAL
Network
|
linuxfoundation fedoraproject
|
nats-server fedora
|
The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-26892
|
2024-11-21 14:20 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208318
|
5.3 |
MEDIUM
Network
|
bouncycastle
|
legion-of-the-bouncy-castle-fips-java-api legion-of-the-bouncy-castle
|
In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inp…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-26939
|
2024-11-21 14:20 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208319
|
4.4 |
MEDIUM
Local
|
trendmicro
|
antivirus
|
Trend Micro Antivirus for Mac 2020 (Consumer) contains an Error Message Information Disclosure vulnerability that if exploited, could allow kernel pointers and debug messages to leak to userland. An …
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-27015
|
2024-11-21 14:20 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208320
|
6.4 |
MEDIUM
Local
|
trendmicro
|
antivirus
|
Trend Micro Antivirus for Mac 2020 (Consumer) contains a race condition vulnerability in the Web Threat Protection Blocklist component, that if exploited, could allow an attacker to case a kernel pan…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2020-27014
|
2024-11-21 14:20 |
2020-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|