CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2020-17444

    Last Modified: 21 Nov 2024

    An issue was discovered in picoTCP 1.7.0. The routine for processing the next header field (and deducing whether the IPv6 extension headers are valid) doesn't check whether the header extension length field would overflow. Therefore, if it wraps around to zero, iterating through the extension headers will not increment the current data pointer. This leads to an infinite loop and Denial-of-Service in pico_ipv6_check_headers_sequence() in pico_ipv6.c.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-17443

    Last Modified: 21 Nov 2024

    An issue was discovered in picoTCP 1.7.0. The code for creating an ICMPv6 echo replies doesn't check whether the ICMPv6 echo request packet's size is shorter than 8 bytes. If the size of the incoming ICMPv6 request packet is shorter than this, the operation that calculates the size of the ICMPv6 echo replies has an integer wrap around, leading to memory corruption and, eventually, Denial-of-Service in pico_icmp6_send_echoreply_not_frag in pico_icmp6.c.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-17442

    Last Modified: 21 Nov 2024

    An issue was discovered in picoTCP 1.7.0. The code for parsing the hop-by-hop IPv6 extension headers does not validate the bounds of the extension header length value, which may result in Integer Wraparound. Therefore, a crafted extension header length value may cause Denial-of-Service because it affects the loop in which the extension headers are parsed in pico_ipv6_process_hopbyhop() in pico_ipv6.c.

    Published: 11 Dec 2020
    9.1
    Critical

    CVE-2020-17441

    Last Modified: 21 Nov 2024

    An issue was discovered in picoTCP 1.7.0. The code for processing the IPv6 headers does not validate whether the IPv6 payload length field is equal to the actual size of the payload, which leads to an Out-of-Bounds read during the ICMPv6 checksum calculation, resulting in either Denial-of-Service or Information Disclosure. This affects pico_ipv6_extension_headers and pico_checksum_adder (in pico_ipv6.c and pico_frame.c).

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-17440

    Last Modified: 21 Nov 2024

    An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets does not validate that domain names present in the DNS responses have '\0' termination. This results in errors when calculating the offset of the pointer that jumps over domain name bytes in DNS response packets when a name lacks this termination, and eventually leads to dereferencing the pointer at an invalid/arbitrary address, within newdata() and parse_name() in resolv.c.

    Published: 11 Dec 2020
    8.3
    High

    CVE-2020-17439

    Last Modified: 21 Nov 2024

    An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets does not validate that the incoming DNS replies match outgoing DNS queries in newdata() in resolv.c. Also, arbitrary DNS replies are parsed if there was any outgoing DNS query with a transaction ID that matches the transaction ID of an incoming reply. Provided that the default DNS cache is quite small (only four records) and that the transaction ID has a very limited set of values that is quite easy to guess, this can lead to DNS cache poisoning.

    Published: 11 Dec 2020
    9.8
    Critical

    CVE-2020-17438

    Last Modified: 21 Nov 2024

    An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that reassembles fragmented packets fails to properly validate the total length of an incoming packet specified in its IP header, as well as the fragmentation offset value specified in the IP header. By crafting a packet with specific values of the IP header length and the fragmentation offset, attackers can write into the .bss section of the program (past the statically allocated buffer that is used for storing the fragmented data) and cause a denial of service in uip_reass() in uip.c, or possibly execute arbitrary code on some target architectures.

    Published: 11 Dec 2020
    5.3
    Medium

    CVE-2020-35175

    Last Modified: 21 Nov 2024

    Frappe Framework 12 and 13 does not properly validate the HTTP method for the frappe.client API.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-13986

    Last Modified: 21 Nov 2024

    An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when handling RPL extension headers of IPv6 network packets in rpl_remove_header in net/rpl/rpl-ext-header.c.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-13985

    Last Modified: 21 Nov 2024

    An issue was discovered in Contiki through 3.0. A memory corruption vulnerability exists in the uIP TCP/IP stack component when handling RPL extension headers of IPv6 network packets in rpl_remove_header in net/rpl/rpl-ext-header.c.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-13984

    Last Modified: 21 Nov 2024

    An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when processing IPv6 extension headers in ext_hdr_options_process in net/ipv6/uip6.c.

    Published: 11 Dec 2020
    6.7
    Medium

    CVE-2020-15375

    Last Modified: 21 Nov 2024

    Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an improper input validation weakness in the command line interface when secccrypptocfg is invoked. The vulnerability could allow a local authenticated user to run arbitrary commands and perform escalation of privileges.

    Published: 11 Dec 2020
    4.3
    Medium

    CVE-2020-15376

    Last Modified: 21 Nov 2024

    Brocade Fabric OS versions before v9.0.0 and after version v8.1.0, configured in Virtual Fabric mode contain a weakness in the ldap implementation that could allow a remote ldap user to login in the Brocade Fibre Channel SAN switch with "user" privileges if it is not associated with any groups.

    Published: 11 Dec 2020
    6.1
    Medium

    CVE-2020-29455

    Last Modified: 21 Nov 2024

    A cross-Site Scripting (XSS) vulnerability in this.showInvalid and this.showInvalidCountry in SmartyStreets liveAddressPlugin.js 3.2 allows remote attackers to inject arbitrary web script or HTML via any address parameter (e.g., street or country).

    Published: 11 Dec 2020
    —
    Unknown

    CVE-2020-35160

    Last Modified: 21 Jun 2024

    CVE ID was once reserved, but never used.

    Published: 11 Dec 2020
    —
    Unknown

    CVE-2020-35161

    Last Modified: 21 Jun 2024

    CVE ID was once reserved, but never used.

    Published: 11 Dec 2020
    —
    Unknown

    CVE-2020-35162

    Last Modified: 21 Jun 2024

    CVE ID was once reserved, but never used.

    Published: 11 Dec 2020
    —
    Unknown

    CVE-2020-35159

    Last Modified: 21 Jun 2024

    CVE ID was once reserved, but never used.

    Published: 11 Dec 2020
    —
    Unknown

    CVE-2020-35157

    Last Modified: 21 Jun 2024

    CVE ID was once reserved, but never used.

    Published: 11 Dec 2020
    —
    Unknown

    CVE-2020-35158

    Last Modified: 21 Jun 2024

    CVE ID was once reserved, but never used.

    Published: 11 Dec 2020
    —
    Unknown

    CVE-2020-35155

    Last Modified: 21 Jun 2024

    CVE ID was once reserved, but never used.

    Published: 11 Dec 2020
    —
    Unknown

    CVE-2020-35156

    Last Modified: 21 Jun 2024

    CVE ID was once reserved, but never used.

    Published: 11 Dec 2020
    —
    Unknown

    CVE-2020-35153

    Last Modified: 21 Jun 2024

    CVE ID was once reserved, but never used.

    Published: 11 Dec 2020
    —
    Unknown

    CVE-2020-35154

    Last Modified: 21 Jun 2024

    CVE ID was once reserved, but never used.

    Published: 11 Dec 2020
    9.8
    Critical

    CVE-2020-27730

    Last Modified: 21 Nov 2024

    In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities.

    Published: 11 Dec 2020
    9.8
    Critical

    CVE-2020-19165

    Last Modified: 21 Nov 2024

    PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-5949

    Last Modified: 21 Nov 2024

    On BIG-IP versions 14.0.0-14.0.1 and 13.1.0-13.1.3.4, certain traffic pattern sent to a virtual server configured with an FTP profile can cause the FTP channel to break.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-27713

    Last Modified: 21 Nov 2024

    In certain configurations on version 13.1.3.4, when a BIG-IP AFM HTTP security profile is applied to a virtual server and the BIG-IP system receives a request with specific characteristics, the connection is reset and the Traffic Management Microkernel (TMM) leaks memory.

    Published: 11 Dec 2020
    5.3
    Medium

    CVE-2020-5950

    Last Modified: 21 Nov 2024

    On BIG-IP 14.1.0-14.1.2.6, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user is granted the admin role.

    Published: 11 Dec 2020
    9.6
    Critical

    CVE-2020-5948

    Last Modified: 21 Nov 2024

    On BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user is granted the admin role.

    Published: 11 Dec 2020
    9.8
    Critical

    CVE-2020-28439

    Last Modified: 21 Nov 2024

    This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package 'corenlp-js-interface.' Vulnerability can be exploited with the following PoC:

    Published: 11 Dec 2020
    9.8
    Critical

    CVE-2020-28440

    Last Modified: 21 Nov 2024

    All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-7791

    Last Modified: 21 Nov 2024

    This affects the package i18n before 2.1.15. Vulnerability arises out of insufficient handling of erroneous language tags in src/i18n/Concrete/TextLocalizer.cs and src/i18n/LocalizedApplication.cs.

    Published: 11 Dec 2020
    6.5
    Medium

    CVE-2020-26264

    Last Modified: 21 Nov 2024

    Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.25 a denial-of-service vulnerability can make a LES server crash via malicious GetProofsV2 request from a connected LES client. This vulnerability only concerns users explicitly enabling les server; disabling les prevents the exploit. The vulnerability was patched in version 1.9.25.

    Published: 11 Dec 2020
    5.3
    Medium

    CVE-2020-26265

    Last Modified: 21 Nov 2024

    Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and before version 1.9.20 a consensus-vulnerability could cause a chain split, where vulnerable versions refuse to accept the canonical chain. The fix was included in the Paragade release version 1.9.20. No individual workaround patches have been made -- all users are recommended to upgrade to a newer version.

    Published: 11 Dec 2020
    9.9
    Critical

    CVE-2020-27134

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 11 Dec 2020
    9.9
    Critical

    CVE-2020-27133

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 11 Dec 2020
    9.9
    Critical

    CVE-2020-27132

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 11 Dec 2020
    9.9
    Critical

    CVE-2020-27127

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 11 Dec 2020
    9.8
    Critical

    CVE-2020-29574

    Last Modified: 7 Nov 2025

    An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.

    Published: 11 Dec 2020
    —
    Unknown

    CVE-2020-35144

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 11 Dec 2020
    6.8
    Medium

    CVE-2020-12148

    Last Modified: 12 Dec 2024

    A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web server running on the EdgeConnect appliance. An attacker could exploit this vulnerability to establish an interactive channel, effectively taking control of the target system. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS versions prior to : 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0.

    Published: 11 Dec 2020
    5.9
    Medium

    CVE-2020-15023

    Last Modified: 21 Nov 2024

    Askey AP5100W devices through AP5100W_Dual_SIG_1.01.097 are affected by WPS PIN offline brute-force cracking. This arises because of issues with the random number selection for the Diffie-Hellman exchange. By capturing an attempted (and even failed) WPS authentication attempt, it is possible to brute force the overall authentication exchange. This allows an attacker to obtain the recovered WPS PIN in minutes or even seconds, and eventually obtain the Wi-Fi PSK key, gaining access to the Wi=Fi network.

    Published: 11 Dec 2020
    6.8
    Medium

    CVE-2020-12149

    Last Modified: 12 Dec 2024

    The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequent shell command, allowing an attacker to manipulate the resulting command by injecting valid OS command input. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS versions prior to: 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0.

    Published: 11 Dec 2020
    9.8
    Critical

    CVE-2020-15357

    Last Modified: 21 Nov 2024

    Network Analysis functionality in Askey AP5100W_Dual_SIG_1.01.097 and all prior versions allows remote attackers to execute arbitrary commands via a shell metacharacter in the ping, traceroute, or route options.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-27508

    Last Modified: 21 Nov 2024

    In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach the 2fa security.

    Published: 11 Dec 2020
    8.8
    High

    CVE-2020-29254

    Last Modified: 21 Nov 2024

    TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected system. An attacker could exploit this vulnerability by persuading a user of the interface to follow a maliciously crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system with the privileges of the user. These action include allowing attackers to submit their own code through an authenticated user resulting in local file Inclusion. If an authenticated user who is able to edit TikiWiki templates visits an malicious website, template code can be edited.

    Published: 11 Dec 2020
    —
    Unknown

    CVE-2020-29589

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-5021. Reason: This candidate is a reservation duplicate of CVE-2019-5021. Notes: All CVE users should reference CVE-2019-5021 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 11 Dec 2020
    —
    Unknown

    CVE-2020-29590

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-5021. Reason: This candidate is a reservation duplicate of CVE-2019-5021. Notes: All CVE users should reference CVE-2019-5021 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 11 Dec 2020
    9.8
    Critical

    CVE-2020-29591

    Last Modified: 21 Nov 2024

    Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of the registry container may allow a remote attacker to achieve root access with a blank password.

    Published: 11 Dec 2020