Unknown · CVSS Not scored
In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.
Published Jun 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Brocade SANnav before version 2.1.1 uses a hard-coded administrator account with the weak password ‘passw0rd’ if a password is not provided for PostgreSQL at install-time.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
wifiscanner.js in thingsSDK WiFi Scanner 1.0.1 allows Code Injection because it can be used with options to overwrite the default executable/binary path and its arguments. An attacker can abuse this functionality to execute arbitrary code.
Published Jun 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.
Published Jun 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory leak, aka CID-28ebeb8db770.
Published Jun 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded opt/axess/AXAssets/default_axess/axess/TR69/Handlers/turbolink/sshkeys/id_rsa SSH key.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in MISP 2.4.128. app/Controller/AttributesController.php has insufficient ACL checks in the attachment downloader.
Published Jun 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
IOBit Malware Fighter Pro 8.0.2.547 allows local users to gain privileges for file deletion by manipulating malicious flagged file locations with an NTFS junction and an Object Manager symbolic link.
Published Jun 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The host SSH servers of Brocade Fabric OS before Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0, and Brocade SANnav before v2.1.1 utilize keys of less than 2048 bits, which may be vulnerable to man-in-the-middle attacks and/or insecure SSH communications.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /registerCpe requests.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Running security scans against the SAN switch can cause config and secnotify processes within the firmware before Brocade Fabric OS v9.0.0, v8.2.2d and v8.2.1e to consume all memory leading to denial of service impacts possibly including a switch panic.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Brocade Fabric OS prior to v9.0.1a and 8.2.3a and after v9.0.0 and 8.2.2d may observe high CPU load during security scanning, which could lead to a slower response to CLI commands and other operations.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opj_image_destroy twice.
Published Jun 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding to allow a user to send an event contact form.
Published Jun 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= for eval injection of Python code.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based buffer over-read in Streams_Fill_PerStream in Multiple/File_MpegPs.cpp (aka an off-by-one during MpegPs parsing).
Published Jun 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileged users (e.g., locations under /var/spool/hylafax that are writable by the uucp account). This allows these users to execute code in the context of the user calling these binaries (often root).
Published Jun 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows escape-sequence injection into the /var/log/axxmpp.log file.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-Side Request Forgery (SSRF).
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Infoblox NIOS before 8.5.2 allows entity expansion during an XML upload operation, a related issue to CVE-2003-1564.
Published Jun 28, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account.
Published Jun 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_user_id_and_key API.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /cnr requests.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Brocade SANnav before version 2.1.1 allows an authenticated attacker to list directories, and list files without permission. As a result, users without permission can see folders, and hidden files, and can create directories without permission.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Nozomi Guardian before 19.0.4 allows attackers to achieve stored XSS (in the web front end) by leveraging the ability to create a custom field with a crafted field name.
Published Jun 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
com.docker.vmnetd in Docker Desktop 2.3.0.3 allows privilege escalation because of a lack of client verification.
Published Jun 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_users" and "select * from Users_users" requests.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Brocade SANnav before version 2.1.1 logs account credentials at the ‘trace’ logging level.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.
Published Jun 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Brocade SANnav before version 2.1.1 contains an Improper Authentication vulnerability that allows cleartext transmission of authentication credentials of the jmx server.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account.
Published Jun 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_instances_for_update API.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /registerCpe requests.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering a triple fault via a request to zero CR3.
Published Jun 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The OVA version of Brocade SANnav before version 2.1.1 installation with IPv6 networking exposes the docker container ports to the network, increasing the potential attack surface.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/mysql chroot directory tree.
Published Jun 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Brocade SANnav before v.2.1.0a could allow remote attackers cause a denial-of-service condition due to a lack of proper validation, of the length of user-supplied data as name for custom field name.
Published Jun 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a /live/GLOBALS API with the CLOUDCNM key.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2 allows post-authentication SQL injection via the site_edit.php typeid or site parameter, the search_incidents_advanced.php search_title parameter, or the report_qbe.php criteriafield parameter.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/axess chroot directory tree.
Published Jun 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account.
Published Jun 29, 2020 · Updated Aug 4, 2024