|
208601
|
5.5 |
MEDIUM
Local
|
huawei
|
nip6800_firmware secospace_usg6600_firmware usg9500_firmware
|
NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid pointer access vulnerability. The software system access an invalid pointer wh…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2020-1875
|
2024-11-21 14:11 |
2020-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208602
|
4.4 |
MEDIUM
Local
|
huawei
|
cloudengine_12800_firmware
|
CloudEngine 12800 with versions of V200R001C00SPC600,V200R001C00SPC700,V200R002C01,V200R002C50SPC800,V200R002C50SPC800PWE,V200R003C00SPC810,V200R003C00SPC810PWE,V200R005C00SPC600,V200R005C00SPC800,V2…
|
NVD-CWE-noinfo
|
CVE-2020-1861
|
2024-11-21 14:11 |
2020-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208603
|
7.8 |
HIGH
Local
|
huawei
|
pcmanager
|
PCManager with versions earlier than 10.0.5.51 have a privilege escalation vulnerability in Huawei PCManager products. An authenticated, local attacker can perform specific operation to exploit this …
|
NVD-CWE-noinfo
|
CVE-2020-1844
|
2024-11-21 14:11 |
2020-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208604
|
5.5 |
MEDIUM
Local
|
huawei
|
honor_v10_firmware
|
Honor V10 smartphones with versions earlier than BKL-AL20 10.0.0.156(C00E156R2P4) and versions earlier than BKL-L09 10.0.0.146(C432E4R1P4) have an out of bounds write vulnerability. The software writ…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-1792
|
2024-11-21 14:11 |
2020-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208605
|
8.8 |
HIGH
Network
|
apache
|
kylin
|
Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.
|
CWE-89
SQL Injection
|
CVE-2020-1937
|
2024-11-21 14:11 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208606
|
9.8 |
CRITICAL
Network
|
apache fedoraproject oracle debian opensuse blackberry netapp
|
tomcat geode fedora transportation_management hospitality_guest_access agile_plm instantis_enterprisetrack mysql_enterprise_monitor health_sciences_empirica_signal communic…
|
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar H…
|
NVD-CWE-Other
|
CVE-2020-1938
|
2024-11-21 14:11 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208607
|
4.8 |
MEDIUM
Network
|
apache debian canonical opensuse netapp oracle
|
tomcat debian_linux ubuntu_linux leap oncommand_system_manager data_availability_services transportation_management hospitality_guest_access retail_order_broker agile_produ…
|
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as va…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-1935
|
2024-11-21 14:11 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208608
|
6.8 |
MEDIUM
Physics
|
huawei
|
hege-560_firmware osca-550_firmware osca-550a_firmware osca-550ax_firmware osca-550x_firmware
|
Huawei HEGE-560 version 1.0.1.20(SP2); OSCA-550 and OSCA-550A version 1.0.0.71(SP1); and OSCA-550AX and OSCA-550X version 1.0.0.71(SP2) have an insufficient authentication vulnerability. An attacker …
|
CWE-287
Improper Authentication
|
CVE-2020-1842
|
2024-11-21 14:11 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208609
|
6.1 |
MEDIUM
Physics
|
huawei
|
hege-560_firmware osca-550_firmware osca-550a_firmware osca-550ax_firmware osca-550x_firmware hege-570_firmware
|
Huawei HEGE-570 version 1.0.1.22(SP3); and HEGE-560, OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X version 1.0.1.21(SP3) have an insufficient verification vulnerability. An attacker can access the d…
|
NVD-CWE-noinfo
|
CVE-2020-1855
|
2024-11-21 14:11 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208610
|
7.8 |
HIGH
Local
|
huawei
|
p30_firmware
|
HUAWEI P30 smartphones with versions earlier than 10.0.0.173(C00E73R1P11) have an improper authentication vulnerability. Due to improperly validation of certain application, an attacker should trick …
|
CWE-287
Improper Authentication
|
CVE-2020-1812
|
2024-11-21 14:11 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|