|
209111
|
8.8 |
HIGH
Network
|
gallagher
|
command_centre
|
Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution. This issue affects: Gallagher Command Centre 8.30 versions prio…
|
CWE-843
Type Confusion
|
CVE-2020-16103
|
2024-11-21 14:06 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209112
|
8.2 |
HIGH
Network
|
gallagher
|
command_centre
|
Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid configuration, potentially causing the server to crash …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-16102
|
2024-11-21 14:06 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209113
|
7.2 |
HIGH
Network
|
gallagher
|
command_centre
|
SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Interfaces' privilege to execute arbitrary SQL against a third…
|
CWE-89
SQL Injection
|
CVE-2020-16104
|
2024-11-21 14:06 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209114
|
6.5 |
MEDIUM
Network
|
bitdefender
|
antivirus_plus
|
An Origin Validation Error vulnerability in the SafePay component of Bitdefender Antivirus Plus allows a web resource to misrepresent itself in the URL bar. This issue affects: Bitdefender Antivirus …
|
CWE-346
Origin Validation Error
|
CVE-2020-15733
|
2024-11-21 14:06 |
2020-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209115
|
3.8 |
LOW
Local
|
canonical
|
ubuntu_linux
|
The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196. This affected versions prior to 1.1.1+bzr982-0ubunt…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-16128
|
2024-11-21 14:06 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209116
|
4.7 |
MEDIUM
Local
|
canonical
|
ubuntu_linux
|
An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a client connection from a snap as coming from a snap if SCM_CREDENTIALS were missi…
|
CWE-362
Race Condition
|
CVE-2020-16123
|
2024-11-21 14:06 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209117
|
9.8 |
CRITICAL
Network
|
ortussolutions
|
testbox
|
In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the application's context) c…
|
CWE-22
Path Traversal
|
CVE-2020-15929
|
2024-11-21 14:06 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209118
|
5.3 |
MEDIUM
Network
|
ortussolutions
|
testbox
|
In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters to test-browser/index.cfm allow directory traversal.
|
CWE-22
Path Traversal
|
CVE-2020-15928
|
2024-11-21 14:06 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209119
|
6.1 |
MEDIUM
Local
|
pulseaudio_project
|
pulseaudio
|
Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. The modargs variable may be freed twice in the fail condition in src/modules/bl…
|
CWE-415
Double Free
|
CVE-2020-15710
|
2024-11-21 14:06 |
2020-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209120
|
7.5 |
HIGH
Network
|
siemens
|
sinumerik_840d_sl_firmware simatic_s7-300_cpu_312_firmware simatic_s7-300_cpu_314_firmware simatic_s7-300_cpu_315-2_dp_firmware simatic_s7-300_cpu_315-2_pn_firmware simatic_s7-300_cpu_…
|
A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC TDC CPU555 (All versions), SINUMERIK 840D sl (All versions). Se…
|
-
|
CVE-2020-15783
|
2024-11-21 14:06 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|