|
196971
|
7.0 |
HIGH
Local
|
siedle
|
sg_150-0_firmware
|
The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 allows local privilege escalation via a race condition in logrotate. By using an exploit chain, an attacker with access to the network can g…
|
CWE-362
Race Condition
|
CVE-2020-9475
|
2024-11-21 14:40 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196972
|
8.8 |
HIGH
Network
|
siedle
|
sg_150-0_firmware
|
The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 allows remote code execution via the backup functionality in the web frontend. By using an exploit chain, an attacker with access to the net…
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-9474
|
2024-11-21 14:40 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196973
|
7.5 |
HIGH
Network
|
huawei
|
oceanstor_5310_firmware
|
Huawei OceanStor 5310 product with version of V500R007C60SPC100 has an invalid pointer access vulnerability. The software system access an invalid pointer when attacker malformed packet. Due to the i…
|
CWE-763
Release of Invalid Pointer or Reference
|
CVE-2020-9098
|
2024-11-21 14:40 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196974
|
4.3 |
MEDIUM
Network
|
mahara
|
mahara
|
In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' i…
|
CWE-200
Information Exposure
|
CVE-2020-9387
|
2024-11-21 14:40 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196975
|
6.5 |
MEDIUM
Network
|
apache
|
nifi_registry
|
If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authentication token on the client side but not on the ser…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-9482
|
2024-11-21 14:40 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196976
|
7.5 |
HIGH
Network
|
apache debian
|
traffic_server debian_linux
|
Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-9481
|
2024-11-21 14:40 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196977
|
9.8 |
CRITICAL
Network
|
fortinet
|
fortimail fortivoice
|
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a l…
|
CWE-287
Improper Authentication
|
CVE-2020-9294
|
2024-11-21 14:40 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196978
|
3.7 |
LOW
Network
|
apache oracle debian qos
|
log4j flexcube_private_banking retail_integration_bus flexcube_core_banking peoplesoft_enterprise_peopletools weblogic_server utilities_framework primavera_unifier retail_cust…
|
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log mess…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-9488
|
2024-11-21 14:40 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196979
|
5.5 |
MEDIUM
Local
|
apache oracle
|
tika flexcube_private_banking primavera_unifier webcenter_portal communications_messaging_server
|
A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3P…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-9489
|
2024-11-21 14:40 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196980
|
9.8 |
CRITICAL
Network
|
dlink
|
dsl-2640b_firmware
|
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A hard-coded account allows management-interface login with high privileges. The logged-in user can perform critical tasks and take fu…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-9279
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|