|
209481
|
9.8 |
CRITICAL
Network
|
apache
|
nuttx
|
Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying and invalid fragmentation offs…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-17529
|
2024-11-21 14:08 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209482
|
9.1 |
CRITICAL
Network
|
apache
|
nuttx
|
Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying arbitrary urgent data pointer …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-17528
|
2024-11-21 14:08 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209483
|
9.8 |
CRITICAL
Network
|
apache
|
tapestry
|
A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deseria…
|
-
|
CVE-2020-17531
|
2024-11-21 14:08 |
2020-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209484
|
5.5 |
MEDIUM
Local
|
apache netapp oracle
|
groovy snapcenter primavera_unifier ilearning business_process_management_suite agile_plm retail_bulk_data_integration communications_services_gatekeeper retail_merchandising_…
|
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method c…
|
NVD-CWE-Other
|
CVE-2020-17521
|
2024-11-21 14:08 |
2020-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209485
|
7.5 |
HIGH
Network
|
apache netapp debian oracle
|
tomcat oncommand_system_manager element_plug-in debian_linux instantis_enterprisetrack sd-wan_edge workload_manager mysql_enterprise_monitor communications_cloud_native_core_b…
|
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream re…
|
CWE-200
Information Exposure
|
CVE-2020-17527
|
2024-11-21 14:08 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209486
|
6.5 |
MEDIUM
Network
|
pbootcms
|
pbootcms
|
Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.
|
CWE-352
Origin Validation Error
|
CVE-2020-17901
|
2024-11-21 14:08 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209487
|
5.3 |
MEDIUM
Network
|
untangle
|
untangle_firewall_ng
|
Untangle Firewall NG before 16.0 uses MD5 for passwords.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-17494
|
2024-11-21 14:08 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209488
|
5.5 |
MEDIUM
Local
|
saltstack debian
|
salt debian_linux
|
The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-17490
|
2024-11-21 14:08 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209489
|
9.8 |
CRITICAL
Network
|
apache debian
|
shiro debian_linux
|
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
|
CWE-287
Improper Authentication
|
CVE-2020-17510
|
2024-11-21 14:08 |
2020-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209490
|
9.6 |
CRITICAL
Network
|
antsword_project
|
antsword
|
A cross-site scripting (XSS) vulnerability AntSword v2.0.7 can remotely execute system commands.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18766
|
2024-11-21 14:08 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|