|
208081
|
5.5 |
MEDIUM
Local
|
imagemagick
|
imagemagick
|
A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service in ImageMagick before 7.0.10-45.
|
-
|
CVE-2020-27829
|
2024-11-21 14:21 |
2021-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208082
|
7.5 |
HIGH
Network
|
lldpd_project openvswitch redhat fedoraproject siemens
|
lldpd openvswitch enterprise_linux virtualization openstack openshift_container_platform fedora simatic_hmi_unified_comfort_panels_firmware simatic_net_cp_1243-1_firmware s…
|
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of…
|
-
|
CVE-2020-27827
|
2024-11-21 14:21 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208083
|
4.3 |
MEDIUM
Physics
|
hamilton-medical
|
hamilton-t1_firmware
|
In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an information disclosure vulnerability in the ventilator allows attackers with physical access to the configuration interface's logs t…
|
-
|
CVE-2020-27290
|
2024-11-21 14:21 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208084
|
7.5 |
HIGH
Network
|
siemens
|
simatic_mv420_firmware simatic_mv440_firmware
|
In SIMATIC MV400 family versions prior to v7.0.6, the ISN generator is initialized with a constant value and has constant increments. An attacker could predict and hijack TCP sessions.
|
NVD-CWE-noinfo
|
CVE-2020-27632
|
2024-11-21 14:21 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208085
|
6.5 |
MEDIUM
Network
|
redhat
|
single_sign-on keycloak
|
A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be …
|
-
|
CVE-2020-27838
|
2024-11-21 14:21 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208086
|
5.4 |
MEDIUM
Network
|
maxum
|
rumpus
|
Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site scripting (XSS). Users are able to create folders in the web application. The folder name is insufficiently validated resulting in a stored cr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27576
|
2024-11-21 14:21 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208087
|
8.8 |
HIGH
Network
|
maxum
|
rumpus
|
Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. The web administration contains functionality in which administrators are able to manage users. The edit users form co…
|
CWE-78
OS Command
|
CVE-2020-27575
|
2024-11-21 14:21 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208088
|
8.8 |
HIGH
Network
|
maxum
|
rumpus
|
Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site request forgery (CSRF). If an authenticated user visits a malicious page, unintended actions could be performed in the web application as the …
|
CWE-352
Origin Validation Error
|
CVE-2020-27574
|
2024-11-21 14:21 |
2021-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208089
|
7.5 |
HIGH
Local
|
gnu redhat fedoraproject netapp
|
grub2 enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux enterprise_linux_server_tus enterprise_linux_server_eus fedora ontap_select_deploy_administration_…
|
A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity…
|
NVD-CWE-Other
|
CVE-2020-27779
|
2024-11-21 14:21 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208090
|
6.7 |
MEDIUM
Local
|
gnu redhat fedoraproject netapp
|
grub2 enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux enterprise_linux_server_tus enterprise_linux_server_eus fedora ontap_select_deploy_administration_…
|
A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line into their corresponding variable contents, using a 1kB stack buffer for temporar…
|
-
|
CVE-2020-27749
|
2024-11-21 14:21 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|