|
210631
|
7.1 |
HIGH
Local
|
huawei
|
honor_v10_firmware
|
Huawei Honor V10 smartphones with versions earlier than 10.0.0.156(C00E156R2P4) has three out of bounds vulnerabilities. Certain driver program does not sufficiently validate certain parameters recei…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-1804
|
2024-11-21 14:11 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210632
|
5.9 |
MEDIUM
Network
|
redhat
|
openshift_container_platform
|
A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during installation. An attacker, able to man-in-the-midd…
|
-
|
CVE-2020-1741
|
2024-11-21 14:11 |
2020-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210633
|
6.1 |
MEDIUM
Network
|
linuxfoundation redhat fedoraproject canonical debian
|
ceph ceph_storage openshift_container_platform fedora ubuntu_linux debian_linux
|
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization o…
|
CWE-79
Cross-site Scripting
|
CVE-2020-1760
|
2024-11-21 14:11 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210634
|
6.5 |
MEDIUM
Local
|
libslirp_project fedoraproject debian opensuse canonical
|
libslirp fedora debian_linux leap ubuntu_linux
|
A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.
|
CWE-416
Use After Free
|
CVE-2020-1983
|
2024-11-21 14:11 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210635
|
8.1 |
HIGH
Network
|
redhat
|
undertow jboss_fuse jboss_enterprise_application_platform single_sign-on jboss_data_grid openshift_application_runtimes
|
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes serv…
|
CWE-20
Improper Input Validation
|
CVE-2020-1757
|
2024-11-21 14:11 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210636
|
7.5 |
HIGH
Network
|
linuxfoundation redhat
|
ceph ceph_storage
|
A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated a…
|
CWE-22
Path Traversal
|
CVE-2020-1699
|
2024-11-21 14:11 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210637
|
7.5 |
HIGH
Network
|
openssl debian freebsd fedoraproject oracle netapp broadcom opensuse jdedwards tenable
|
openssl debian_linux freebsd fedora peoplesoft_enterprise_peopletools jd_edwards_world_security enterprise_manager_ops_center mysql enterprise_manager_base_platform mysql_e…
|
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signat…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-1967
|
2024-11-21 14:11 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210638
|
5.3 |
MEDIUM
Adjacent
|
huawei
|
honor_v20_firmware
|
Huawei smartphones Honor V20 with versions earlier than 10.0.0.179(C636E3R4P3),versions earlier than 10.0.0.180(C185E3R3P3),versions earlier than 10.0.0.180(C432E10R3P4) have an information disclosur…
|
CWE-287
Improper Authentication
|
CVE-2020-1803
|
2024-11-21 14:11 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210639
|
7.0 |
HIGH
Local
|
gnu redhat canonical
|
glibc enterprise_linux ubuntu_linux
|
An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when stor…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-1751
|
2024-11-21 14:11 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210640
|
9.8 |
CRITICAL
Network
|
apache
|
heron
|
It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to prevent the instantiation of arbitrary types, resu…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-1964
|
2024-11-21 14:11 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|