LiveActive security incident?Get immediate response
CVE archive

August 2020

Browse CVE records published in August 2020, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1514 matching CVEs · Page 9 of 31.

Unknown · CVSS Not scored

CVE-2020-27795: A segmentation fault was discovered in radare2 with adf command.

A segmentation fault was discovered in radare2 with adf command. In libr/core/cmd_anal.c, when command "adf" has no or wrong argument, anal_fcn_data (core, input + 1) --> RAnalFunction *fcn = r_anal_get_fcn_in (core->anal, core->offset, -1); returns null pointer for fcn causing segmentation fault later in ensure_fcn_range (fcn).

Published Aug 19, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-27836: A flaw was found in cluster-ingress-operator.

A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability..

Published Aug 22, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-26938: In oauth2-server (aka node-oauth2-server) through 3.1.1, the value of the redirect_uri parameter received d...

In oauth2-server (aka node-oauth2-server) through 3.1.1, the value of the redirect_uri parameter received during the authorization and token request is checked against an incorrect URI pattern ("[a-zA-Z][a-zA-Z0-9+.-]+:") before making a redirection. This allows a malicious client to pass an XSS payload through the redirect_uri parameter while making an authorization request. NOTE: this vulnerability is similar to CVE-2020-7741.

Published Aug 29, 2022 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-25928: The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Buffer Overflow.

The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: DNS response processing functions: dns_upcall(), getoffset(), dnc_set_answer(). The attack vector is: a specific DNS response packet. The code does not check the "response data length" field of individual DNS answers, which may cause out-of-bounds read/write operations, leading to Information leak, Denial-or-Service, or Remote Code Execution, depending on the context.

Published Aug 18, 2021 · Updated Aug 4, 2024

Medium · CVSS 6.5

CVE-2020-26064: A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacke...

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by persuading a user to import a crafted XML file with malicious entries. A successful exploit could allow the attacker to read and write files within the affected application.

Published Aug 4, 2023 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-25927: The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Out-of-bounds Read.

The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Out-of-bounds Read. The impact is: a denial of service (remote). The component is: DNS response processing in function: dns_upcall(). The attack vector is: a specific DNS response packet. The code does not check whether the number of queries/responses specified in the DNS packet header corresponds to the query/response data available in the DNS packet.

Published Aug 18, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-25767: An issue was discovered in HCC Embedded NicheStack IPv4 4.1.

An issue was discovered in HCC Embedded NicheStack IPv4 4.1. The dnc_copy_in routine for parsing DNS domain names does not check whether a domain name compression pointer is pointing within the bounds of the packet (e.g., forward compression pointer jumps are allowed), which leads to an Out-of-bounds Read, and a Denial-of-Service as a consequence.

Published Aug 18, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-25565: In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password...

In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once the access is available, the attacker can inject malicious OS commands on “ping”, “traceroute” and “snmp” functions and execute code on the server.

Published Aug 11, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-25560: In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password...

In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once the access is available, the attacker can inject malicious OS commands on “ping”, “traceroute” and “snmp” functions and execute code on the server. We also observed the same is true if the JSESSIONID is completely removed.

Published Aug 11, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-25359: An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6.

An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers the ability to send a crafted request to /lib/ajaxHandlers/ajaxDeleteAllLoggingFiles.php by specifying a path in the path parameter and an extension in the ext parameter and delete all the files with that extension in that path.

Published Aug 20, 2021 · Updated Aug 4, 2024