|
212251
|
5.4 |
MEDIUM
Network
|
openstack canonical
|
keystone ubuntu_linux
|
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then …
|
CWE-347 CWE-294
Improper Verification of Cryptographic Signature Authentication Bypass by Capture-replay
|
CVE-2020-12692
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212252
|
8.8 |
HIGH
Network
|
openstack canonical
|
keystone ubuntu_linux
|
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a project that they have a specified role on, and then …
|
CWE-863
Incorrect Authorization
|
CVE-2020-12691
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212253
|
8.8 |
HIGH
Network
|
openstack
|
keystone
|
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a key…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-12690
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212254
|
8.8 |
HIGH
Network
|
openstack canonical
|
keystone ubuntu_linux
|
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application credential) can create an EC2 credential with an escala…
|
CWE-269
Improper Privilege Management
|
CVE-2020-12689
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212255
|
8.8 |
HIGH
Network
|
dolibarr
|
dolibarr
|
core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric menu parameter.
|
CWE-20
Improper Input Validation
|
CVE-2020-12669
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212256
|
7.5 |
HIGH
Network
|
graphicsmagick debian opensuse
|
graphicsmagick debian_linux leap backports_sle
|
GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12672
|
2024-11-21 14:00 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212257
|
6.1 |
MEDIUM
Network
|
go-macaron fedoraproject
|
macaron fedora
|
macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL.
|
CWE-601
Open Redirect
|
CVE-2020-12666
|
2024-11-21 14:00 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212258
|
6.7 |
MEDIUM
Local
|
linux netapp
|
linux_kernel cloud_backup steelstore_cloud_integrated_storage solidfire_\&_hci_management_node active_iq_unified_manager solidfire_baseboard_management_controller hci_baseboard_…
|
An issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write (by a user with the CAP_NET_ADMIN capability) because of a lack of headroom val…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12659
|
2024-11-21 14:00 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212259
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bfq_idle_slice_timer_body.
|
CWE-416
Use After Free
|
CVE-2020-12657
|
2024-11-21 14:00 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212260
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
An issue was discovered in xfs_agf_verify in fs/xfs/libxfs/xfs_alloc.c in the Linux kernel through 5.6.10. Attackers may trigger a sync of excessive duration via an XFS v5 image with crafted metadata…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-12655
|
2024-11-21 14:00 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|