|
196771
|
7.8 |
HIGH
Local
|
huawei
|
honor_20_pro_firmware mate_20_firmware mate_20_pro_firmware mate_20_x_firmware p30_firmware p30_pro_firmware hima-l29c_firmware laya-al00ep_firmware princeton-al10b_firmware
|
There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overfl…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-9247
|
2024-11-21 14:40 |
2020-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196772
|
7.8 |
HIGH
Local
|
huawei
|
nova_4_firmware sydneym-al00_firmware
|
HUAWEI nova 4 versions earlier than 10.0.0.165(C01E34R2P4) and SydneyM-AL00 versions earlier than 10.0.0.165(C00E66R1P5) have an out-of-bounds read and write vulnerability. An attacker with specific …
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-9117
|
2024-11-21 14:40 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196773
|
7.8 |
HIGH
Local
|
huawei
|
fusioncompute
|
FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper privilege management, an attacker with common privilege may access some specific…
|
CWE-269
Improper Privilege Management
|
CVE-2020-9114
|
2024-11-21 14:40 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196774
|
7.2 |
HIGH
Network
|
huawei
|
fusioncompute
|
Huawei FusionCompute versions 6.5.1 and 8.0.0 have a command injection vulnerability. An authenticated, remote attacker can craft specific request to exploit this vulnerability. Due to insufficient v…
|
CWE-77
Command Injection
|
CVE-2020-9116
|
2024-11-21 14:40 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196775
|
7.2 |
HIGH
Network
|
huawei
|
manageone
|
ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command injection vulnerability. An attacker with high privileges may exploit this vul…
|
CWE-20 CWE-77
Improper Input Validation Command Injection
|
CVE-2020-9115
|
2024-11-21 14:40 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196776
|
6.7 |
MEDIUM
Local
|
huawei
|
mate_30_firmware
|
HUAWEI Mate 30 versions earlier than 10.1.0.159(C00E159R7P2) have a vulnerability of improper buffer operation. Due to improper restrictions, local attackers with high privileges can exploit the vuln…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-9129
|
2024-11-21 14:40 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196777
|
6.7 |
MEDIUM
Local
|
huawei
|
nip6300_firmware nip6600_firmware secospace_usg6300_firmware secospace_usg6500_firmware secospace_usg6600_firmware usg9500_firmware
|
Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some malicious codes in some files of the affected produc…
|
CWE-20 CWE-77
Improper Input Validation Command Injection
|
CVE-2020-9127
|
2024-11-21 14:40 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196778
|
4.4 |
MEDIUM
Local
|
huawei
|
fusioncompute
|
FusionCompute versions 8.0.0 have an insecure encryption algorithm vulnerability. Attackers with high permissions can exploit this vulnerability to cause information leak.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-9128
|
2024-11-21 14:40 |
2020-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196779
|
6.5 |
MEDIUM
Network
|
netflix
|
dispatch
|
The Access Control issues include allowing a regular user to view a restricted incident, user role escalation to admin, users adding themselves as a participant in a restricted incident, and users ab…
|
NVD-CWE-Other
|
CVE-2020-9300
|
2024-11-21 14:40 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196780
|
5.4 |
MEDIUM
Network
|
netflix
|
dispatch
|
There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Priority, Incident Type, Tag Type, and Incident Filter. This …
|
CWE-79
Cross-site Scripting
|
CVE-2020-9299
|
2024-11-21 14:40 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|