|
211781
|
8.8 |
HIGH
Network
|
fossil-scm fedoraproject opensuse
|
fossil fedora leap backports_sle
|
Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.
|
CWE-862
Missing Authorization
|
CVE-2020-24614
|
2024-11-21 14:15 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211782
|
8.1 |
HIGH
Network
|
fasterxml netapp oracle debian
|
jackson-databind active_iq_unified_manager application_testing_suite agile_plm communications_policy_management communications_diameter_signaling_router communications_services_gate…
|
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-24616
|
2024-11-21 14:15 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211783
|
6.8 |
MEDIUM
Network
|
wolfssl
|
wolfssl
|
wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, within SanityCheckTls13MsgReceived() in tls13.c. This is an incorrect implementation of the TLS 1.3 client state machine…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-24613
|
2024-11-21 14:15 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211784
|
8.8 |
HIGH
Network
|
raspap
|
raspap
|
An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misconfigured (and virtually unrestricted) web console to attack the underlying OS (…
|
CWE-78
OS Command
|
CVE-2020-24572
|
2024-11-21 14:15 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211785
|
4.7 |
MEDIUM
Local
|
fedoraproject
|
selinux-policy
|
An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config/Yubico directory is mishandled. Consequently, when SELinux is in enforced mode…
|
CWE-287
Improper Authentication
|
CVE-2020-24612
|
2024-11-21 14:15 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211786
|
7.5 |
HIGH
Network
|
squid-cache canonical debian fedoraproject opensuse
|
squid ubuntu_linux debian_linux fedora leap
|
Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only o…
|
CWE-667
Improper Locking
|
CVE-2020-24606
|
2024-11-21 14:15 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211787
|
6.5 |
MEDIUM
Network
|
wso2
|
identity_server_analytics api_microgateway api_manager enterprise_integrator api_manager_analytics
|
The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0,…
|
CWE-611
XXE
|
CVE-2020-24591
|
2024-11-21 14:15 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211788
|
9.1 |
CRITICAL
Network
|
wso2
|
api_microgateway api_manager
|
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
|
CWE-776
XML Entity Expansion
|
CVE-2020-24590
|
2024-11-21 14:15 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211789
|
9.1 |
CRITICAL
Network
|
wso2
|
api_microgateway api_manager
|
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
|
CWE-611
XXE
|
CVE-2020-24589
|
2024-11-21 14:15 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211790
|
5.3 |
MEDIUM
Network
|
wolfssl
|
wolfssl
|
An issue was discovered in the DTLS handshake implementation in wolfSSL before 4.5.0. Clear DTLS application_data messages in epoch 0 do not produce an out-of-order error. Instead, these messages are…
|
NVD-CWE-noinfo
|
CVE-2020-24585
|
2024-11-21 14:15 |
2020-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|