Show filters
4,245 Total Results
Displaying 641-650 of 4,245
Sort by:
Attacker Value
Unknown
CVE-2019-18860
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi.
0
Attacker Value
Unknown
CVE-2019-14855
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.
0
Attacker Value
Unknown
CVE-2020-10669
Disclosure Date: March 19, 2020 (last updated February 21, 2025)
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to authentication bypass on the page /home.jsp. An unauthenticated attacker able to connect to the device's web interface can get a copy of the documents uploaded by any users. NOTE: this is fixed in the latest version.
0
Attacker Value
Unknown
CVE-2020-10671
Disclosure Date: March 19, 2020 (last updated February 21, 2025)
The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-wide issue. An attacker could perform administrative actions by targeting a logged-in administrative user. NOTE: this is fixed in the latest version.
0
Attacker Value
Unknown
CVE-2020-10667
Disclosure Date: March 19, 2020 (last updated February 21, 2025)
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Stored XSS in /TemplateManager/indexExternalLocation.jsp. The vulnerable parameter is map(template_name). NOTE: this is fixed in the latest version.
0
Attacker Value
Unknown
CVE-2020-10670
Disclosure Date: March 19, 2020 (last updated February 21, 2025)
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in the parameter settingId of the settingDialogContent.jsp page. NOTE: this is fixed in the latest version.
0
Attacker Value
Unknown
CVE-2020-10668
Disclosure Date: March 19, 2020 (last updated February 21, 2025)
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in /home.jsp. The vulnerable parameter is openSI. NOTE: this is fixed in the latest version.
0
Attacker Value
Unknown
CVE-2020-0556
Disclosure Date: March 12, 2020 (last updated November 27, 2024)
Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access
0
Attacker Value
Unknown
CVE-2020-10531
Disclosure Date: March 12, 2020 (last updated February 21, 2025)
An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.
0
Attacker Value
Unknown
CVE-2020-10108
Disclosure Date: March 12, 2020 (last updated February 21, 2025)
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.
0