|
209011
|
7.5 |
HIGH
Network
|
altran
|
picotcp
|
An issue was discovered in picoTCP 1.7.0. The code for parsing the hop-by-hop IPv6 extension headers does not validate the bounds of the extension header length value, which may result in Integer Wra…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-17442
|
2024-11-21 14:08 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209012
|
9.1 |
CRITICAL
Network
|
altran microchip
|
picotcp mplab_harmony
|
An issue was discovered in picoTCP 1.7.0. The code for processing the IPv6 headers does not validate whether the IPv6 payload length field is equal to the actual size of the payload, which leads to a…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-17441
|
2024-11-21 14:08 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209013
|
7.5 |
HIGH
Network
|
uip_project
|
uip
|
An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets does not validate that domain names present in the DNS responses have '\0' ter…
|
NVD-CWE-Other
|
CVE-2020-17440
|
2024-11-21 14:08 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209014
|
8.3 |
HIGH
Network
|
uip_project
|
uip
|
An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets does not validate that the incoming DNS replies match outgoing DNS queries in …
|
CWE-20
Improper Input Validation
|
CVE-2020-17439
|
2024-11-21 14:08 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209015
|
9.8 |
CRITICAL
Network
|
uip_project
|
uip
|
An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that reassembles fragmented packets fails to properly validate the total length of an incoming packet specified…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-17438
|
2024-11-21 14:08 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209016
|
8.2 |
HIGH
Network
|
uip_project open-iscsi_project siemens
|
uip open-iscsi sentron_3va_com100_firmware sentron_3va_com800_firmware sentron_3va_dsp800_firmware sentron_pac2200_clp_firmware sentron_pac2200_firmware sentron_pac3200_firmware<…
|
An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts t…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-17437
|
2024-11-21 14:08 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209017
|
6.1 |
MEDIUM
Network
|
apache
|
airflow
|
The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions prior to 1.10.13. This is same as CVE-2020-13944 but t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-17515
|
2024-11-21 14:08 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209018
|
9.8 |
CRITICAL
Network
|
apache oracle
|
struts business_intelligence communications_policy_management financial_services_data_integration_hub hospitality_opera_5 communications_pricing_design_center mysql_enterprise_monit…
|
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2020-17530
|
2024-11-21 14:08 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209019
|
9.8 |
CRITICAL
Network
|
idreamsoft
|
icms
|
iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php.
|
CWE-78
OS Command
|
CVE-2020-19142
|
2024-11-21 14:08 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209020
|
9.8 |
CRITICAL
Network
|
apache
|
nuttx
|
Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying and invalid fragmentation offs…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-17529
|
2024-11-21 14:08 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|