|
196271
|
5.5 |
MEDIUM
Local
|
huawei
|
taurus-al00b_firmware
|
Huawei smart phone Taurus-AL00B with versions earlier than 10.0.0.203(C00E201R7P2) have a use-after-free (UAF) vulnerability. An authenticated, local attacker may perform specific operations to explo…
|
CWE-416
Use After Free
|
CVE-2020-9065
|
2024-11-21 14:39 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196272
|
6.5 |
MEDIUM
Network
|
google
|
closure_library
|
A URL parsing issue in goog.uri of the Google Closure Library versions up to and including v20200224 allows an attacker to send malicious URLs to be parsed by the library and return the wrong authori…
|
NVD-CWE-noinfo
|
CVE-2020-8910
|
2024-11-21 14:39 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196273
|
6.1 |
MEDIUM
Network
|
dart
|
dart_software_development_kit
|
An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an attacker leveraging DOM Clobbering techniques to skip the sanitization and inject c…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8923
|
2024-11-21 14:39 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196274
|
9.8 |
CRITICAL
Network
|
zend
|
zendto
|
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to gain administrative access with a large number of r…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2020-8986
|
2024-11-21 14:39 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196275
|
8.8 |
HIGH
Network
|
zend
|
zendto
|
ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2020-8985
|
2024-11-21 14:39 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196276
|
7.5 |
HIGH
Network
|
zend
|
zendto
|
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.
|
CWE-346
Origin Validation Error
|
CVE-2020-8984
|
2024-11-21 14:39 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196277
|
9.8 |
CRITICAL
Network
|
quest
|
foglight_evolve
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0. Authentication is not required to exploit this vulnerability. The specif…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-8868
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196278
|
6.5 |
MEDIUM
Network
|
horde debian
|
groupware horde_form debian_linux
|
This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-8866
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196279
|
6.3 |
MEDIUM
Network
|
horde debian
|
groupware debian_linux
|
This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. Th…
|
CWE-22
Path Traversal
|
CVE-2020-8865
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196280
|
7.5 |
HIGH
Network
|
psi
|
electronic_logbook
|
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ELOG Electronic Logbook 3.1.4-283534d. Authentication is not required to exploit this v…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-8859
|
2024-11-21 14:39 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|