|
217901
|
9.8 |
CRITICAL
Network
|
qualcomm
|
ipq4019_firmware ipq6018_firmware ipq8064_firmware ipq8074_firmware qca4531_firmware qca9531_firmware qca9980_firmware
|
u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity,…
|
CWE-77
Command Injection
|
CVE-2020-11117
|
2024-11-21 13:56 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
217902
|
7.8 |
HIGH
Local
|
qualcomm
|
apq8009_firmware apq8096au_firmware apq8098_firmware bitra_firmware mdm9607_firmware mdm9650_firmware msm8917_firmware msm8920_firmware msm8937_firmware msm8940_firmware
|
u'Possible out of bound access while copying the mask file content into the buffer without checking the buffer size' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Indust…
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-11128
|
2024-11-21 13:56 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
217903
|
7.8 |
HIGH
Local
|
qualcomm
|
apq8096au_firmware apq8098_firmware bitra_firmware kamorta_firmware msm8917_firmware msm8953_firmware msm8998_firmware qcm2150_firmware qcs405_firmware qcs605_firmware q…
|
u'Calling thread may free the data buffer pointer that was passed to the callback and later when event loop executes the callback, data buffer may not be valid and will lead to use after free scenari…
|
CWE-416
Use After Free
|
CVE-2020-11120
|
2024-11-21 13:56 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
217904
|
7.5 |
HIGH
Network
|
qualcomm
|
apq8009_firmware apq8017_firmware apq8053_firmware apq8096au_firmware apq8098_firmware bitra_firmware kamorta_firmware mdm9150_firmware mdm9206_firmware mdm9207c_firmware
|
u'Information exposure issues while processing IE header due to improper check of beacon IE frame' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Con…
|
CWE-20
Improper Input Validation
|
CVE-2020-11118
|
2024-11-21 13:56 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
217905
|
9.8 |
CRITICAL
Network
|
qualcomm
|
apq8009_firmware apq8053_firmware apq8096au_firmware apq8098_firmware bitra_firmware kamorta_firmware mdm9206_firmware mdm9207c_firmware mdm9607_firmware mdm9640_firmware
|
u'Possible out of bound write while processing association response received from host due to lack of check of IE length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Conne…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-11116
|
2024-11-21 13:56 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
217906
|
7.5 |
HIGH
Network
|
qualcomm
|
apq8009_firmware apq8053_firmware apq8096au_firmware apq8098_firmware bitra_firmware kamorta_firmware mdm9206_firmware mdm9207c_firmware mdm9607_firmware mdm9640_firmware
|
u'Buffer over read occurs while processing information element from beacon due to lack of check of data received from beacon' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics C…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-11115
|
2024-11-21 13:56 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
217907
|
5.3 |
MEDIUM
Network
|
oracle redhat
|
virtualization ovirt-engine
|
An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the tar…
|
CWE-601
Open Redirect
|
CVE-2020-10775
|
2024-11-21 13:56 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
217908
|
6.3 |
MEDIUM
Network
|
redhat
|
cloudforms_management_engine
|
Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula …
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-10780
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
217909
|
8.3 |
HIGH
Network
|
redhat
|
cloudforms
|
Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group can perform actions restricted only to EVM-Super-administrator group, leads to,…
|
NVD-CWE-noinfo
|
CVE-2020-10783
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
217910
|
6.5 |
MEDIUM
Network
|
redhat
|
cloudforms
|
Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right cri…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-10779
|
2024-11-21 13:56 |
2020-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|