|
197391
|
7.8 |
HIGH
Local
|
linux fedoraproject canonical netapp
|
linux_kernel fedora ubuntu_linux cloud_backup steelstore_cloud_integrated_storage solidfire hci_management_node a700s_firmware 8300_firmware 8700_firmware a400_firmware<…
|
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel …
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-8835
|
2024-11-21 14:39 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197392
|
6.1 |
MEDIUM
Network
|
tiki
|
tikiwiki_cms\/groupware
|
There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows maliciou…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8966
|
2024-11-21 14:39 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197393
|
5.4 |
MEDIUM
Network
|
versiant
|
lynx_customer_service_portal
|
Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malicious JavaScript that is stor…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9055
|
2024-11-21 14:39 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197394
|
4.3 |
MEDIUM
Network
|
kubernetes fedoraproject
|
kubernetes fedora
|
The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-8552
|
2024-11-21 14:39 |
2020-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197395
|
6.5 |
MEDIUM
Adjacent
|
kubernetes fedoraproject
|
kubernetes fedora
|
The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-8551
|
2024-11-21 14:39 |
2020-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197396
|
7.8 |
HIGH
Local
|
huawei
|
oxfordp-an10b_firmware
|
Huawei smartphones OxfordP-AN10B with versions earlier than 10.0.1.169(C00E166R4P1) have an improper authentication vulnerability. The Application doesn't perform proper authentication when user perf…
|
CWE-287
Improper Authentication
|
CVE-2020-9066
|
2024-11-21 14:39 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197397
|
5.5 |
MEDIUM
Local
|
huawei
|
taurus-al00b_firmware
|
Huawei smart phone Taurus-AL00B with versions earlier than 10.0.0.203(C00E201R7P2) have a use-after-free (UAF) vulnerability. An authenticated, local attacker may perform specific operations to explo…
|
CWE-416
Use After Free
|
CVE-2020-9065
|
2024-11-21 14:39 |
2020-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197398
|
6.5 |
MEDIUM
Network
|
google
|
closure_library
|
A URL parsing issue in goog.uri of the Google Closure Library versions up to and including v20200224 allows an attacker to send malicious URLs to be parsed by the library and return the wrong authori…
|
NVD-CWE-noinfo
|
CVE-2020-8910
|
2024-11-21 14:39 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197399
|
6.1 |
MEDIUM
Network
|
dart
|
dart_software_development_kit
|
An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an attacker leveraging DOM Clobbering techniques to skip the sanitization and inject c…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8923
|
2024-11-21 14:39 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197400
|
9.8 |
CRITICAL
Network
|
zend
|
zendto
|
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to gain administrative access with a large number of r…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2020-8986
|
2024-11-21 14:39 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|