Show filters
817 Total Results
Displaying 621-630 of 817
Sort by:
Attacker Value
Unknown

CVE-2020-12706

Disclosure Date: May 07, 2020 (last updated October 06, 2023)
Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_admin.php
Attacker Value
Unknown

CVE-2020-3188

Disclosure Date: May 06, 2020 (last updated November 27, 2024)
A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for management connections could allow an unauthenticated, remote attacker to cause a buildup of remote management connections to an affected device, which could result in a denial of service (DoS) condition. The vulnerability exists because the default session timeout period for specific to-the-box remote management connections is too long. An attacker could exploit this vulnerability by sending a large and sustained number of crafted remote management connections to an affected device, resulting in a buildup of those connections over time. A successful exploit could allow the attacker to cause the remote management interface or Cisco Firepower Device Manager (FDM) to stop responding and cause other management functions to go offline, resulting in a DoS condition. The user traffic that is flowing through the device would not be affected, and the DoS condition would be isolated to remote mana…
Attacker Value
Unknown

CVE-2020-11734

Disclosure Date: April 13, 2020 (last updated November 27, 2024)
cgi-bin/go in CyberSolutions CyberMail 5 or later allows XSS via the ACTION parameter.
Attacker Value
Unknown

CVE-2020-9500

Disclosure Date: April 09, 2020 (last updated November 27, 2024)
Some products of Dahua have Denial of Service vulnerabilities. After the successful login of the legal account, the attacker sends a specific log query command, which may cause the device to go down.
Attacker Value
Unknown

CVE-2020-9499

Disclosure Date: April 09, 2020 (last updated November 27, 2024)
Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker sends a specific DDNS test command, which may cause the device to go down.
Attacker Value
Unknown

CVE-2019-13559

Disclosure Date: April 07, 2020 (last updated November 27, 2024)
GE Mark VIe Controller is shipped with pre-configured hard-coded credentials that may allow root-user access to the controller. A limited application of the affected product may ship without setup and configuration instructions immediately available to the end user. The bulk of controllers go into applications requiring the GE commissioning engineer to change default configurations during the installation process. GE recommends that users reset controller passwords during installation in the operating environment.
Attacker Value
Unknown

CVE-2020-5300

Disclosure Date: April 06, 2020 (last updated November 27, 2024)
In Hydra (an OAuth2 Server and OpenID Certified™ OpenID Connect Provider written in Go), before version 1.4.0+oryOS.17, when using client authentication method 'private_key_jwt' [1], OpenId specification says the following about assertion `jti`: "A unique identifier for the token, which can be used to prevent reuse of the token. These tokens MUST only be used once, unless conditions for reuse were negotiated between the parties". Hydra does not check the uniqueness of this `jti` value. Exploiting this vulnerability is somewhat difficult because: - TLS protects against MITM which makes it difficult to intercept valid tokens for replay attacks - The expiry time of the JWT gives only a short window of opportunity where it could be replayed This has been patched in version v1.4.0+oryOS.17
Attacker Value
Unknown

CVE-2020-7007

Disclosure Date: March 24, 2020 (last updated November 27, 2024)
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the attacker may execute arbitrary codes or target the device, causing it to go out of service.
Attacker Value
Unknown

CVE-2019-20611

Disclosure Date: March 24, 2020 (last updated November 27, 2024)
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), Go(8.1), P(9.0), and Go(9.0) (Exynos chipsets) software. A baseband stack overflow leads to arbitrary code execution. The Samsung ID is SVE-2019-13963 (April 2019).
Attacker Value
Unknown

CVE-2020-7919

Disclosure Date: March 16, 2020 (last updated November 08, 2023)
Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.