|
198091
|
5.3 |
MEDIUM
Network
|
intel
|
active_management_technology_firmware service_manager
|
Out-of-bounds read in DHCPv6 subsystem in Intel(R) AMT and Intel(R)ISM versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64 and 14.0.33 may allow an unauthenticated user to potentially enable informa…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-8674
|
2024-11-21 14:39 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198092
|
5.4 |
MEDIUM
Network
|
openbrowser_project
|
openbrowser
|
OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens another app in the browser can be manipulated]
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-8954
|
2024-11-21 14:39 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198093
|
8.8 |
HIGH
Network
|
couchbase
|
couchbase_server
|
In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to check the results of a REST API request.
|
CWE-352
Origin Validation Error
|
CVE-2020-9042
|
2024-11-21 14:39 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198094
|
7.5 |
HIGH
Network
|
couchbase
|
sync_gateway couchbase_server
|
In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text search endpoints are vulnerable to the Slowloris denial-of-service attack becau…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2020-9041
|
2024-11-21 14:39 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198095
|
7.5 |
HIGH
Network
|
couchbase
|
couchbase_server_java_sdk
|
Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can leverage this flaw by crafting a cryptographically vali…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-9040
|
2024-11-21 14:39 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198096
|
6.3 |
MEDIUM
Network
|
kubernetes fedoraproject
|
kubernetes fedora
|
The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows cert…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-8555
|
2024-11-21 14:39 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198097
|
5.3 |
MEDIUM
Network
|
huawei
|
honor_20_pro_firmware honor_view_20_firmware honor_20_firmware
|
Huawei Smartphones HONOR 20 PRO;Honor View 20;HONOR 20 have an improper handling of exceptional condition Vulnerability. A component cannot deal with an exception correctly. Attackers can exploit thi…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-9074
|
2024-11-21 14:39 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198098
|
9.8 |
CRITICAL
Network
|
gesio
|
erp
|
There is an improper Neutralization of Special Elements used in an SQL Command (SQL Injection) vulnerability in php files of GESIO ERP. GESIO ERP all versions prior to 11.2 allows malicious users to …
|
CWE-89
SQL Injection
|
CVE-2020-8967
|
2024-11-21 14:39 |
2020-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198099
|
6.5 |
MEDIUM
Network
|
huawei
|
ar120-s_firmware ar1200_firmware ar1200-s_firmware ar150_firmware ar150-s_firmware ar160_firmware ar200_firmware ar200-s_firmware ar2200_firmware ar2200-s_firmware ar320…
|
There is a few bytes out-of-bounds read vulnerability in some Huawei products. The software reads data past the end of the intended buffer when parsing certain message, an authenticated attacker coul…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-9071
|
2024-11-21 14:39 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198100
|
7.2 |
HIGH
Network
|
pi-hole
|
pi-hole
|
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
|
CWE-78
OS Command
|
CVE-2020-8816
|
2024-11-21 14:39 |
2020-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|