|
199861
|
3.7 |
LOW
Network
|
apache oracle debian qos
|
log4j flexcube_private_banking retail_integration_bus flexcube_core_banking peoplesoft_enterprise_peopletools weblogic_server utilities_framework primavera_unifier retail_cust…
|
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log mess…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-9488
|
2024-11-21 14:40 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199862
|
5.5 |
MEDIUM
Local
|
apache oracle
|
tika flexcube_private_banking primavera_unifier webcenter_portal communications_messaging_server
|
A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3P…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-9489
|
2024-11-21 14:40 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199863
|
9.8 |
CRITICAL
Network
|
dlink
|
dsl-2640b_firmware
|
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A hard-coded account allows management-interface login with high privileges. The logged-in user can perform critical tasks and take fu…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-9279
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199864
|
9.1 |
CRITICAL
Network
|
dlink
|
dsl-2640b_firmware
|
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by accessing an unauthenticated URL.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-9278
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199865
|
9.8 |
CRITICAL
Network
|
dlink
|
dsl-2640b_firmware
|
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modules. This allows one to perform administrative tasks (e.g., modify the admin pas…
|
CWE-287
Improper Authentication
|
CVE-2020-9277
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199866
|
8.8 |
HIGH
Network
|
dlink
|
dsl-2640b_firmware
|
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The function do_cgi(), which processes cgi requests supplied to the device's web servers, is vulnerable to a remotely exploitable stac…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-9276
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199867
|
9.8 |
CRITICAL
Network
|
dlink
|
dsl-2640b_firmware
|
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A cfm UDP service listening on port 65002 allows remote, unauthenticated exfiltration of administrative credentials.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-9275
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199868
|
6.1 |
MEDIUM
Network
|
zulip
|
zulip_server
|
Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.
|
CWE-79
Cross-site Scripting
|
CVE-2020-9445
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199869
|
6.1 |
MEDIUM
Network
|
zulip
|
zulip_server
|
Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality.
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-9444
|
2024-11-21 14:40 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199870
|
8.8 |
HIGH
Network
|
microfocus
|
enterprise_developer enterprise_server
|
Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6. The v…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-9523
|
2024-11-21 14:40 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|