|
209901
|
9.8 |
CRITICAL
Network
|
apache debian
|
shiro debian_linux
|
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
|
NVD-CWE-noinfo
|
CVE-2020-1957
|
2024-11-21 14:11 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209902
|
9.8 |
CRITICAL
Network
|
pyyaml fedoraproject opensuse oracle
|
pyyaml fedora leap communications_cloud_native_core_network_function_cloud_native_environment
|
A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method …
|
-
|
CVE-2020-1747
|
2024-11-21 14:11 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209903
|
5.6 |
MEDIUM
Network
|
redhat
|
keycloak
|
A flaw was found in keycloak before version 9.0.1. When configuring an Conditional OTP Authentication Flow as a post login flow of an IDP, the failure login events for OTP are not being sent to the b…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-1744
|
2024-11-21 14:11 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209904
|
9.8 |
CRITICAL
Network
|
apache debian
|
traffic_server debian_linux
|
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-1944
|
2024-11-21 14:11 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209905
|
5.5 |
MEDIUM
Local
|
apache oracle debian canonical
|
tika flexcube_private_banking debian_linux business_process_management_suite ubuntu_linux communications_messaging_server
|
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-1951
|
2024-11-21 14:11 |
2020-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209906
|
5.5 |
MEDIUM
Local
|
apache oracle debian canonical
|
tika flexcube_private_banking debian_linux business_process_management_suite ubuntu_linux communications_messaging_server
|
A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-1950
|
2024-11-21 14:11 |
2020-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209907
|
5.5 |
MEDIUM
Local
|
huawei
|
oxfords-an00a_firmware
|
Huawei smartphone OxfordS-AN00A with versions earlier than 10.0.1.152D(C735E152R3P3),versions earlier than 10.0.1.160(C00E160R4P1) have an improper authentication vulnerability. Authentication to tar…
|
CWE-287
Improper Authentication
|
CVE-2020-1878
|
2024-11-21 14:11 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209908
|
3.9 |
LOW
Physics
|
huawei
|
hege-560_firmware hege-570_firmware osca-550_firmware osca-550a_firmware osca-550ax_firmware osca-550x_firmware
|
There is an improper integrity checking vulnerability on some huawei products. The software of the affected product has an improper integrity check which may allow an attacker with high privilege to …
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-1879
|
2024-11-21 14:11 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209909
|
8.1 |
HIGH
Network
|
huawei
|
secospace_antiddos8000_firmware
|
Some Huawei products have a security vulnerability due to improper authentication. A remote attacker needs to obtain some information and forge the peer device to send specific packets to the affecte…
|
CWE-287
Improper Authentication
|
CVE-2020-1864
|
2024-11-21 14:11 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209910
|
3.3 |
LOW
Local
|
huawei
|
campusinsight manageone
|
There is a double free vulnerability in some Huawei products. A local attacker with low privilege may perform some operations to exploit the vulnerability. Due to doubly freeing memory, successful ex…
|
CWE-415
Double Free
|
CVE-2020-1862
|
2024-11-21 14:11 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|