|
196251
|
5.5 |
MEDIUM
Local
|
huawei
|
taurus-al00b_firmware
|
Huawei smartphones Taurus-AL00B with versions earlier than 10.0.0.205(C00E201R7P2) have an improper authentication vulnerability. The software insufficiently validate the user's identity when a user …
|
CWE-287
Improper Authentication
|
CVE-2020-9070
|
2024-11-21 14:39 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196252
|
7.8 |
HIGH
Local
|
sierrawireless
|
mobile_broadband_driver_package
|
The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to overwrite arbitrary files in arbitrary folders using hard links. An unprivileged u…
|
CWE-59
Link Following
|
CVE-2020-8948
|
2024-11-21 14:39 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196253
|
8.8 |
HIGH
Network
|
wowza
|
streaming_engine
|
A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any read-only user to issue requests to the administration panel in order to change functi…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-9004
|
2024-11-21 14:39 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196254
|
5.4 |
MEDIUM
Network
|
periscopeholdings
|
buyspeed
|
Periscope BuySpeed version 14.5 is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to store arbitrary JavaScript within the application. This JavaScript i…
|
CWE-79
Cross-site Scripting
|
CVE-2020-9056
|
2024-11-21 14:39 |
2020-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196255
|
9.8 |
CRITICAL
Network
|
avira
|
free_antivirus
|
An issue was discovered in Avira Free-Antivirus before 15.0.2004.1825. The Self-Protection feature does not prohibit a write operation from an external process. Thus, code injection can be used to tu…
|
NVD-CWE-noinfo
|
CVE-2020-8961
|
2024-11-21 14:39 |
2020-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196256
|
8.8 |
HIGH
Network
|
argoproj
|
argo_cd
|
As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privil…
|
CWE-287 CWE-1188
Improper Authentication Insecure Default Initialization of Resource
|
CVE-2020-8828
|
2024-11-21 14:39 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196257
|
7.5 |
HIGH
Network
|
argoproj
|
argo_cd
|
As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. Attackers can submit an unlimited number of authenti…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-8827
|
2024-11-21 14:39 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196258
|
7.5 |
HIGH
Network
|
argoproj
|
argo_cd
|
As of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication tokens, once issued, were usable forever without expiration—there was no refresh or forced re-authen…
|
CWE-384
Session Fixation
|
CVE-2020-8826
|
2024-11-21 14:39 |
2020-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196259
|
5.5 |
MEDIUM
Local
|
canonical netapp
|
ubuntu_linux cloud_backup steelstore_cloud_integrated_storage solidfire_\&_hci_management_node aff_8300_firmware aff_8700_firmware aff_a220_firmware aff_a320_firmware aff_…
|
The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discover…
|
CWE-200
Information Exposure
|
CVE-2020-8832
|
2024-11-21 14:39 |
2020-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196260
|
6.5 |
MEDIUM
Local
|
linux canonical opensuse
|
linux_kernel ubuntu_linux leap
|
KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc_{save,restore}_tm, leading to a stack corruption. Because of t…
|
CWE-362
Race Condition
|
CVE-2020-8834
|
2024-11-21 14:39 |
2020-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|