|
208331
|
7.5 |
HIGH
Network
|
motion_project
|
motion
|
A Denial of Service condition in Motion-Project Motion 3.2 through 4.3.1 allows remote unauthenticated users to cause a webu.c segmentation fault and kill the main process via a crafted HTTP request.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-26566
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208332
|
7.8 |
HIGH
Local
|
kde
|
partition_manager
|
An issue was discovered in KDE Partition Manager 4.1.0 before 4.2.0. The kpmcore_externalcommand helper contains a logic flaw in which the service invoking D-Bus is not properly checked. An attacker …
|
NVD-CWE-noinfo
|
CVE-2020-27187
|
2024-11-21 14:20 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208333
|
7.0 |
HIGH
Local
|
eclipse netapp oracle apache debian
|
jetty snap_creator_framework snapcenter vasa_provider virtual_storage_console storage_replication_adapter flexcube_private_banking communications_offline_mediation_controller …
|
In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between al…
|
NVD-CWE-Other
|
CVE-2020-27216
|
2024-11-21 14:20 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208334
|
8.8 |
HIGH
Network
|
belkin
|
linksys_wrt_160nl_firmware
|
Belkin LINKSYS WRT160NL 1.0.04.002_US_20130619 devices have a stack-based buffer overflow vulnerability because of sprintf in create_dir in mini_httpd. Successful exploitation leads to arbitrary code…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-26561
|
2024-11-21 14:20 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208335
|
7.8 |
HIGH
Local
|
avm
|
fritz\!box_7490_firmware
|
FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism.
|
NVD-CWE-noinfo
|
CVE-2020-26887
|
2024-11-21 14:20 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208336
|
9.1 |
CRITICAL
Network
|
hashicorp
|
nomad
|
HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6
|
NVD-CWE-noinfo
|
CVE-2020-27195
|
2024-11-21 14:20 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208337
|
7.5 |
HIGH
Network
|
octopus
|
octopus_deploy
|
An issue was discovered in Octopus Deploy through 2020.4.4. If enabled, the websocket endpoint may allow an untrusted tentacle host to present itself as a trusted one.
|
NVD-CWE-noinfo
|
CVE-2020-27155
|
2024-11-21 14:20 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208338
|
5.3 |
MEDIUM
Network
|
atomx
|
atomxcms
|
AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php
|
CWE-22 CWE-668
Path Traversal Exposure of Resource to Wrong Sphere
|
CVE-2020-26650
|
2024-11-21 14:20 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208339
|
8.1 |
HIGH
Network
|
atomx
|
atomxcms_2
|
AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php
|
CWE-306 CWE-862
Missing Authentication for Critical Function Missing Authorization
|
CVE-2020-26649
|
2024-11-21 14:20 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208340
|
5.3 |
MEDIUM
Network
|
lightning_network_daemon_project
|
lightning_network_daemon
|
Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can be exploited by an…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-26895
|
2024-11-21 14:20 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|