|
207991
|
6.5 |
MEDIUM
Network
|
sap
|
netweaver_application_server_java
|
Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) without proper file format validation, leading to …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-26826
|
2024-11-21 14:20 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207992
|
7.6 |
HIGH
Network
|
sap
|
s\/4_hana netweaver_application_server_abap
|
SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), version…
|
CWE-862
Missing Authorization
|
CVE-2020-26832
|
2024-11-21 14:20 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207993
|
8.1 |
HIGH
Network
|
sap
|
solution_manager
|
SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks for an authenticated user. Due to inadequate access control, a network attacker a…
|
CWE-862
Missing Authorization
|
CVE-2020-26830
|
2024-11-21 14:20 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207994
|
10.0 |
CRITICAL
Network
|
sap
|
netweaver_application_server_java
|
SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication check, that are outside…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-26829
|
2024-11-21 14:20 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207995
|
4.5 |
MEDIUM
Adjacent
|
sap
|
netweaver_application_server_java
|
SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in the SAP NetWeaver AS Java Key Storage service stored in the database in…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-26816
|
2024-11-21 14:20 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207996
|
8.8 |
HIGH
Network
|
mozilla
|
thunderbird
|
When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-26970
|
2024-11-21 14:20 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207997
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-26969
|
2024-11-21 14:20 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207998
|
8.8 |
HIGH
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-26968
|
2024-11-21 14:20 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207999
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox Screenshots into interacting with elements other than those that it injected into the page. This w…
|
NVD-CWE-noinfo
|
CVE-2020-26967
|
2024-11-21 14:20 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208000
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; resulting in an information leak. *Note: Th…
|
NVD-CWE-Other
|
CVE-2020-26966
|
2024-11-21 14:20 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|