|
198311
|
2.4 |
LOW
Physics
|
lenovo
|
thinkcentre_e73_firmware thinkcentre_m73_firmware qitian_4500_firmware qitian_b4550_firmware qitian_m4550_firmware thinkcentre_m4500k_firmware thinkcentre_m4500t_firmware thinkce…
|
In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration changes.
|
NVD-CWE-noinfo
|
CVE-2020-8352
|
2024-11-21 14:38 |
2020-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198312
|
7.5 |
HIGH
Network
|
json8-merge-patch_project
|
json8-merge-patch
|
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.
|
CWE-20
Improper Input Validation
|
CVE-2020-8268
|
2024-11-21 14:38 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198313
|
4.1 |
MEDIUM
Local
|
nextcloud
|
nextcloud_server
|
A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-8150
|
2024-11-21 14:38 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198314
|
5.3 |
MEDIUM
Network
|
nextcloud
|
nextcloud_server
|
A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-8133
|
2024-11-21 14:38 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198315
|
5.5 |
MEDIUM
Local
|
brave
|
brave
|
The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the timestamp of when the user last opened an incognito window, including Tor windows. T…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-8276
|
2024-11-21 14:38 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198316
|
5.3 |
MEDIUM
Network
|
ui
|
unifi_protect_firmware
|
A security issue was found in UniFi Protect controller v1.14.10 and earlier.The authentication in the UniFi Protect controller API was using “x-token” improperly, allowing attackers to use the API to…
|
CWE-287
Improper Authentication
|
CVE-2020-8267
|
2024-11-21 14:38 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198317
|
7.5 |
HIGH
Network
|
tcpdump debian fedoraproject apple
|
tcpdump debian_linux fedora mac_os_x macos
|
The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-8037
|
2024-11-21 14:38 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198318
|
7.5 |
HIGH
Network
|
tcpdump
|
tcpdump
|
The tok2strbuf() function in tcpdump 4.10.0-PRE-GIT was used by the SOME/IP dissector in an unsafe way.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-8036
|
2024-11-21 14:38 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198319
|
6.8 |
MEDIUM
Physics
|
nextcloud
|
nextcloud_server
|
A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not …
|
CWE-287
Improper Authentication
|
CVE-2020-8236
|
2024-11-21 14:38 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198320
|
7.5 |
HIGH
Network
|
nextcloud
|
nextcloud_server
|
A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-8183
|
2024-11-21 14:38 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|