π¨ CVE-2020-13528
An information disclosure vulnerability exists in the Web Manager and telnet CLI functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause information disclosure. An attacker can sniff the network to trigger this vulnerability.
π@cveNotify
An information disclosure vulnerability exists in the Web Manager and telnet CLI functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause information disclosure. An attacker can sniff the network to trigger this vulnerability.
π@cveNotify
π¨ CVE-2020-27640
The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet phones with firmware before 1.5.3 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.
π@cveNotify
The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet phones with firmware before 1.5.3 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.
π@cveNotify
π¨ CVE-2020-1953
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.
π@cveNotify
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore load and execute code out of the control of the host application.
π@cveNotify
π¨ CVE-2020-29389
The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Linux Docker container deployed by affected versions of the Docker image may allow an attacker to achieve root access with a blank password.
π@cveNotify
The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Linux Docker container deployed by affected versions of the Docker image may allow an attacker to achieve root access with a blank password.
π@cveNotify
GitHub
CVE/CVE-2020-29389 at main Β· koharin/CVE
Contribute to koharin/CVE development by creating an account on GitHub.
π¨ CVE-2020-22083
** DISPUTED ** jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documented behaviour. pickle is known to be capable of causing arbitrary code execution, and must not be used with un-trusted data.
π@cveNotify
** DISPUTED ** jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documented behaviour. pickle is known to be capable of causing arbitrary code execution, and must not be used with un-trusted data.
π@cveNotify
Redhat
CVE-2020-22083 - Red Hat Customer Portal
CVE Details App
π¨ CVE-2020-13931
If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is misconfigured, a JMX port is opened on TCP port 1099, which does not include authentication. CVE-2020-11969 previously addressed the creation of the JMX management interface, however the incomplete fix did not cover this edge case.
π@cveNotify
If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is misconfigured, a JMX port is opened on TCP port 1099, which does not include authentication. CVE-2020-11969 previously addressed the creation of the JMX management interface, however the incomplete fix did not cover this edge case.
π@cveNotify
π¨ CVE-2020-28460
This affects the package multi-ini before 2.1.2. It is possible to pollute an object's prototype by specifying the constructor.proto object as part of an array. This is a bypass of CVE-2020-28448.
π@cveNotify
This affects the package multi-ini before 2.1.2. It is possible to pollute an object's prototype by specifying the constructor.proto object as part of an array. This is a bypass of CVE-2020-28448.
π@cveNotify
GitHub
Fixed 2nd issue with prototype pollution Β· evangelion1204/multi-ini@6b2212b
Read multilevel and multiline ini files in compatible with Zend. - evangelion1204/multi-ini
π¨ CVE-2020-28448
This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto object as part of an array.
π@cveNotify
This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto object as part of an array.
π@cveNotify
GitHub
Fix prototype pollution by evangelion1204 Β· Pull Request #37 Β· evangelion1204/multi-ini
Fixed prototype pollution by ignoring __proto__ in sections and keys.
Steps to reproduce
payload.ini
[__proto__]
polluted = "polluted"
poc.js:
var ini = require('multi-ini...
Steps to reproduce
payload.ini
[__proto__]
polluted = "polluted"
poc.js:
var ini = require('multi-ini...
π¨ CVE-2020-29564
The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user. System using the Consul Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password.
π@cveNotify
The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user. System using the Consul Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password.
π@cveNotify
GitHub
CVE/CVE-2020-29564 at main Β· koharin/CVE
Contribute to koharin/CVE development by creating an account on GitHub.
π¨ CVE-2020-29575
The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. Systems using the elixir Linux Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password.
π@cveNotify
The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. Systems using the elixir Linux Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password.
π@cveNotify
π¨ CVE-2020-29576
The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
π@cveNotify
The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
π@cveNotify
GitHub
CVE/CVE-2020-29576 at main Β· koharin/CVE
Contribute to koharin/CVE development by creating an account on GitHub.
π¨ CVE-2020-26198
Dell EMC iDRAC9 versions prior to 4.32.10.00 and 4.40.00.00 contain a reflected cross-site scripting vulnerability in the iDRAC9 web application. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victimβs browser by tricking a victim in to following a specially crafted link.
π@cveNotify
Dell EMC iDRAC9 versions prior to 4.32.10.00 and 4.40.00.00 contain a reflected cross-site scripting vulnerability in the iDRAC9 web application. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victimβs browser by tricking a victim in to following a specially crafted link.
π@cveNotify
Dell
DSA-2020-268: Dell EMC iDRAC9 Reflected XSS Vulnerability | Dell UK
Dell EMC iDRAC has been updated to address a vulnerability that may be exploited to compromise the affected systems.
π¨ CVE-2020-29577
The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
π@cveNotify
The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
π@cveNotify
π¨ CVE-2020-29578
The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.
π@cveNotify
The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.
π@cveNotify
π¨ CVE-2020-17520
In the Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verification mechanism by constructing special URLs, thereby accessing any HTTP API.
π@cveNotify
In the Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verification mechanism by constructing special URLs, thereby accessing any HTTP API.
π@cveNotify
π¨ CVE-2019-11781
Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to trick victims into modifying their account via crafted links, leading to privilege escalation.
π@cveNotify
Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to trick victims into modifying their account via crafted links, leading to privilege escalation.
π@cveNotify
GitHub
[SEC] CVE-2019-11781 - Affects: Odoo 12.0 and earlier (Community an... Β· Issue #63706 Β· odoo/odoo
Security Advisory - CVE-2019-11781 Affects: Odoo 12.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2019-11781 Component: Portal Credits: "iamsushi" Improper input v...
π¨ CVE-2019-11784
Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to obtain access to arbitrary messages in conversations they were not a party to.
π@cveNotify
Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to obtain access to arbitrary messages in conversations they were not a party to.
π@cveNotify
GitHub
[SEC] CVE-2019-11784 - Affects: Odoo 14.0 and earlier (Community an... Β· Issue #63709 Β· odoo/odoo
Security Advisory - CVE-2019-11784 Affects: Odoo 14.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2019-11784 Component: Discuss Improper access control in mail module (notifications...
π¨ CVE-2019-11786
Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to modify translated terms, which may lead to arbitrary content modification on translatable elements.
π@cveNotify
Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to modify translated terms, which may lead to arbitrary content modification on translatable elements.
π@cveNotify
GitHub
[SEC] CVE-2019-11786 - Affects: Odoo 13.0 and earlier (Community an... Β· Issue #63711 Β· odoo/odoo
Security Advisory - CVE-2019-11786 Affects: Odoo 13.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2019-11786 Component: Core Credits: Martin Trigaux, Alexandre Diaz Improper access ...
π¨ CVE-2018-15632
Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty database on which they can connect with default credentials.
π@cveNotify
Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty database on which they can connect with default credentials.
π@cveNotify
GitHub
[SEC] CVE-2018-15632 - Affects: Odoo 11.0 and earlier (Community an... Β· Issue #63700 Β· odoo/odoo
Security Advisory - CVE-2018-15632 Affects: Odoo 11.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2018-15632 Component: Framework Credits: P. Valov (SoCyber) Improper input validati...
π¨ CVE-2018-15633
Cross-site scripting (XSS) issue in "document" module in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted attachment filenames.
π@cveNotify
Cross-site scripting (XSS) issue in "document" module in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted attachment filenames.
π@cveNotify
GitHub
[SEC] CVE-2018-15633 - Affects: Odoo 11.0 and earlier (Community an... Β· Issue #63701 Β· odoo/odoo
Security Advisory - CVE-2018-15633 Affects: Odoo 11.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2018-15633 Component: "document" module Credits: Nathanael ROTA (...
π¨ CVE-2018-15634
Cross-site scripting (XSS) issue in attachment management in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via a crafted link.
π@cveNotify
Cross-site scripting (XSS) issue in attachment management in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via a crafted link.
π@cveNotify
GitHub
[SEC] CVE-2018-15634 - Affects: Odoo 14.0 and earlier (Community an... Β· Issue #63702 Β· odoo/odoo
Security Advisory - CVE-2018-15634 Affects: Odoo 14.0 and earlier (Community and Enterprise Editions) CVE ID: CVE-2018-15634 Component: Framework Credits: Nathanael ROTA (Capgemini) and Alessandro ...