|
209661
|
9.8 |
CRITICAL
Network
|
openclinic_ga_project
|
openclinic_ga
|
OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks, which may allow u…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-14494
|
2024-11-21 14:03 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209662
|
6.5 |
MEDIUM
Network
|
openclinic_ga_project
|
openclinic_ga
|
OpenClinic GA versions 5.09.02 and 5.89.05b do not properly check permissions before executing SQL queries, which may allow a low-privilege user to access privileged information.
|
CWE-862
Missing Authorization
|
CVE-2020-14491
|
2024-11-21 14:03 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209663
|
9.8 |
CRITICAL
Network
|
openclinic_ga_project
|
openclinic_ga
|
OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted request to initiate a session with limited functionality, which may allow exec…
|
CWE-287
Improper Authentication
|
CVE-2020-14485
|
2024-11-21 14:03 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209664
|
9.8 |
CRITICAL
Network
|
openclinic_ga_project
|
openclinic_ga
|
OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass the system’s account lockout protection, which may allow brute force password attacks.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-14484
|
2024-11-21 14:03 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209665
|
7.3 |
HIGH
Local
|
oracle
|
solaris
|
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Utility). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged …
|
NVD-CWE-noinfo
|
CVE-2020-14724
|
2024-11-21 14:03 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209666
|
8.2 |
HIGH
Network
|
oracle
|
help_technologies
|
Vulnerability in the Oracle Help Technologies product of Oracle Fusion Middleware (component: Web UIX). Supported versions that are affected are 11.1.1.9.0 and 12.2.1.3.0. Easily exploitable vulnerab…
|
NVD-CWE-noinfo
|
CVE-2020-14723
|
2024-11-21 14:03 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209667
|
5.8 |
MEDIUM
Network
|
oracle
|
enterprise_communications_broker
|
Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications Applications (component: WebGUI). Supported versions that are affected are 3.0.0-3.2.0. Difficult to expl…
|
NVD-CWE-noinfo
|
CVE-2020-14722
|
2024-11-21 14:03 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209668
|
6.3 |
MEDIUM
Network
|
oracle
|
enterprise_communications_broker
|
Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications Applications (component: WebGUI). Supported versions that are affected are 3.0.0-3.2.0. Easily exploitabl…
|
NVD-CWE-noinfo
|
CVE-2020-14721
|
2024-11-21 14:03 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209669
|
7.7 |
HIGH
Network
|
oracle
|
internet_expenses
|
Vulnerability in the Oracle Internet Expenses product of Oracle E-Business Suite (component: Mobile Expenses Admin Utilities). Supported versions that are affected are 12.2.4-12.2.9. Easily exploitab…
|
NVD-CWE-noinfo
|
CVE-2020-14720
|
2024-11-21 14:03 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209670
|
9.8 |
CRITICAL
Network
|
moxa
|
edr-g902-t_firmware edr-g902_firmware edr-g903-t_firmware edr-g903_firmware
|
Malicious operation of the crafted web browser cookie may cause a stack-based buffer overflow in the system web server on the EDR-G902 and EDR-G903 Series Routers (versions prior to 5.4).
|
CWE-787
Out-of-bounds Write
|
CVE-2020-14511
|
2024-11-21 14:03 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|