|
208441
|
7.5 |
HIGH
Network
|
honeywell
|
opc_ua_tunneller
|
Some parsing functions in the affected product do not check the return value of malloc and the thread handling the message is forced to close, which may lead to a denial-of-service condition on the O…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2020-27274
|
2024-11-21 14:20 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208442
|
7.8 |
HIGH
Local
|
deltaww
|
tpeditor
|
TPEditor (v1.98 and prior) is vulnerable to two out-of-bounds write instances in the way it processes project files, allowing an attacker to craft a special project file that may permit arbitrary cod…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-27284
|
2024-11-21 14:20 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208443
|
7.8 |
HIGH
Local
|
deltaww
|
ispsoft
|
A use after free issue has been identified in the way ISPSoft(v3.12 and prior) processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution.
|
CWE-416
Use After Free
|
CVE-2020-27280
|
2024-11-21 14:20 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208444
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible way to access contacts due to a permissions bypass. This could lead to local information disclosure with no additional …
|
NVD-CWE-noinfo
|
CVE-2020-27098
|
2024-11-21 14:20 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208445
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. Use…
|
NVD-CWE-noinfo
|
CVE-2020-27097
|
2024-11-21 14:20 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208446
|
5.5 |
MEDIUM
Local
|
eset
|
security mail_security file_security endpoint_security endpoint_antivirus smart_security internet_security nod32_antivirus
|
A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwrite (deletion) of any file via a symlink, due to insecure permissions. The poss…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-26941
|
2024-11-21 14:20 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208447
|
9.8 |
CRITICAL
Network
|
eclipse
|
openj9
|
In Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encod…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-27221
|
2024-11-21 14:20 |
2021-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208448
|
5.7 |
MEDIUM
Adjacent
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications lacks replay protection measur…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2020-27269
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208449
|
6.5 |
MEDIUM
Adjacent
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically pro…
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2020-27268
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208450
|
6.5 |
MEDIUM
Adjacent
|
sooil
|
anydana-a_firmware anydana-i_firmware diabecare_rs_firmware
|
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically pro…
|
CWE-287
Improper Authentication
|
CVE-2020-27266
|
2024-11-21 14:20 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|