|
196391
|
5.5 |
MEDIUM
Local
|
linux canonical opensuse netapp
|
linux_kernel ubuntu_linux leap cloud_backup steelstore_cloud_integrated_storage data_availability_services solidfire hci_management_node active_iq_unified_manager h410c_fir…
|
ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size.
|
CWE-400 CWE-834
Uncontrolled Resource Consumption Excessive Iteration
|
CVE-2020-8992
|
2024-11-21 14:39 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196392
|
2.3 |
LOW
Local
|
redhat
|
lvm2
|
vg_lookup in daemons/lvmetad/lvmetad-core.c in LVM2 2.02 mismanages memory, leading to an lvmetad memory leak, as demonstrated by running pvs. NOTE: RedHat disputes CVE-2020-8991 as not being a vulne…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-8991
|
2024-11-21 14:39 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196393
|
5.3 |
MEDIUM
Network
|
voatz
|
voatz
|
In the Voatz application 2020-01-01 for Android, the amount of data transmitted during a single voter's vote depends on the different lengths of the metadata across the available voting choices, whic…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-8989
|
2024-11-21 14:39 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196394
|
5.9 |
MEDIUM
Network
|
voatz
|
voatz
|
The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover log…
|
CWE-330 CWE-521
Use of Insufficiently Random Values Weak Password Requirements
|
CVE-2020-8988
|
2024-11-21 14:39 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196395
|
6.1 |
MEDIUM
Network
|
mantisbt
|
source_integration
|
A cross-site scripting (XSS) vulnerability was discovered in the Source Integration plugin before 1.6.2 and 2.x before 2.3.1 for MantisBT. The repo_delete.php Delete Repository page allows execution …
|
CWE-79
Cross-site Scripting
|
CVE-2020-8981
|
2024-11-21 14:39 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196396
|
6.5 |
MEDIUM
Network
|
salesagility
|
suitecrm
|
SuiteCRM through 7.11.10 allows SQL Injection via the SOAP API, the EmailUIAjax interface, or the MailMerge module.
|
CWE-89
SQL Injection
|
CVE-2020-8804
|
2024-11-21 14:39 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196397
|
9.8 |
CRITICAL
Network
|
salesagility
|
suitecrm
|
SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.
|
CWE-22
Path Traversal
|
CVE-2020-8803
|
2024-11-21 14:39 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196398
|
9.8 |
CRITICAL
Network
|
salesagility
|
suitecrm
|
SuiteCRM through 7.11.11 has Incorrect Access Control via action_saveHTMLField Bean Manipulation.
|
CWE-89
SQL Injection
|
CVE-2020-8802
|
2024-11-21 14:39 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196399
|
7.2 |
HIGH
Network
|
salesagility
|
suitecrm
|
SuiteCRM through 7.11.11 allows PHAR Deserialization.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-8801
|
2024-11-21 14:39 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196400
|
8.8 |
HIGH
Network
|
salesagility
|
suitecrm
|
SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.
|
CWE-74
Injection
|
CVE-2020-8800
|
2024-11-21 14:39 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|