|
199591
|
6.1 |
MEDIUM
Network
|
mozilla
|
webthings_gateway
|
A reflected XSS vulnerability exists within the gateway, allowing an attacker to craft a specialized URL which could steal the user's authentication token. When combined with CVE-2020-6803, an attack…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6804
|
2024-11-21 14:36 |
2020-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199592
|
6.1 |
MEDIUM
Network
|
mozilla
|
webthings_gateway
|
An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site after logging in.
|
CWE-601
Open Redirect
|
CVE-2020-6803
|
2024-11-21 14:36 |
2020-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199593
|
5.3 |
MEDIUM
Network
|
php tenable debian opensuse
|
php tenable.sc debian_linux leap
|
In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (06…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-7063
|
2024-11-21 14:36 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199594
|
7.5 |
HIGH
Network
|
php opensuse debian canonical
|
php leap debian_linux ubuntu_linux
|
In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set …
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-7062
|
2024-11-21 14:36 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199595
|
9.1 |
CRITICAL
Network
|
php tenable
|
php tenable.sc
|
In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated …
|
CWE-125
Out-of-bounds Read
|
CVE-2020-7061
|
2024-11-21 14:36 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199596
|
9.1 |
CRITICAL
Network
|
openfortivpn_project fedoraproject opensuse
|
openfortivpn fedora leap backports_sle
|
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonst…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-7043
|
2024-11-21 14:36 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199597
|
5.3 |
MEDIUM
Network
|
openfortivpn_project fedoraproject opensuse
|
openfortivpn fedora leap backports_sle
|
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outco…
|
CWE-295 CWE-908
Improper Certificate Validation Use of Uninitialized Resource
|
CVE-2020-7042
|
2024-11-21 14:36 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199598
|
5.3 |
MEDIUM
Network
|
openfortivpn_project fedoraproject opensuse
|
openfortivpn fedora leap backports_sle
|
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a suc…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-7041
|
2024-11-21 14:36 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199599
|
6.5 |
MEDIUM
Adjacent
|
zte
|
e8820v3_firmware
|
ZTE E8820V3 router product is impacted by an information leak vulnerability. Attackers could use this vulnerability to to gain wireless passwords. After obtaining the wireless password, the attacker …
|
NVD-CWE-noinfo
|
CVE-2020-6864
|
2024-11-21 14:36 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199600
|
6.5 |
MEDIUM
Adjacent
|
zte
|
e8820v3_firmware
|
ZTE E8820V3 router product is impacted by a permission and access control vulnerability. Attackers could use this vulnerability to tamper with DDNS parameters and send DoS attacks on the specified UR…
|
NVD-CWE-noinfo
|
CVE-2020-6863
|
2024-11-21 14:36 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|