Show filters
1,297 Total Results
Displaying 331-340 of 1,297
Sort by:
Attacker Value
Unknown

CVE-2020-17515

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions prior to 1.10.13. This is same as CVE-2020-13944 but the implemented fix in Airflow 1.10.13 did not fix the issue completely.
Attacker Value
Unknown

CVE-2020-28251

Disclosure Date: December 03, 2020 (last updated November 28, 2024)
NETSCOUT AirMagnet Enterprise 11.1.4 build 37257 and earlier has a sensor escalated privileges vulnerability that can be exploited to provide someone with administrative access to a sensor, with credentials to invoke a command to provide root access to the operating system. The attacker must complete a straightforward password-cracking exercise.
Attacker Value
Unknown

CVE-2020-26509

Disclosure Date: November 16, 2020 (last updated February 22, 2025)
Airleader Master and Easy <= 6.21 devices have default credentials that can be used for a denial of service.
Attacker Value
Unknown

CVE-2020-26510

Disclosure Date: November 16, 2020 (last updated February 22, 2025)
Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for deployment of a new .war file, with resultant remote code execution.
Attacker Value
Unknown

CVE-2020-13927

Disclosure Date: November 10, 2020 (last updated February 22, 2025)
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and is documented at https://airflow.apache.org/docs/1.10.11/security.html#api-authentication. Note this change fixes it for new installs but existing users need to change their config to default `[api]auth_backend = airflow.api.auth.backend.deny_all` as mentioned in the Updating Guide: https://github.com/apache/airflow/blob/1.10.11/UPDATING.md#experimental-api-will-deny-all-request-by-default
Attacker Value
Unknown

CVE-2020-7129

Disclosure Date: November 04, 2020 (last updated November 28, 2024)
A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
Attacker Value
Unknown

CVE-2020-7128

Disclosure Date: November 04, 2020 (last updated February 22, 2025)
A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
Attacker Value
Unknown

CVE-2019-7291

Disclosure Date: October 27, 2020 (last updated November 28, 2024)
A denial of service issue was addressed with improved memory handling. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. An attacker in a privileged position may be able to perform a denial of service attack.
Attacker Value
Unknown

CVE-2019-8572

Disclosure Date: October 27, 2020 (last updated February 22, 2025)
A null pointer dereference was addressed with improved input validation. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A remote attacker may be able to cause arbitrary code execution.
Attacker Value
Unknown

CVE-2019-8580

Disclosure Date: October 27, 2020 (last updated November 28, 2024)
Source-routed IPv4 packets were disabled by default. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. Source-routed IPv4 packets may be unexpectedly accepted.