CVE-2020-8910
A URL parsing issue in goog.uri of the Google Closure Library versions up to and including v20200224 allows an attacker to send malicious URLs to be parsed by the library and return the wrong...
A URL parsing issue in goog.uri of the Google Closure Library versions up to and including v20200224 allows an attacker to send malicious URLs to be parsed by the library and return the wrong...
In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive parameters can result in the Sensitive parameters ending up in the impact analysis report. Date published : 2020-03-26...
DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows local users to execute arbitrary code via execution from a compromised folder. Date published : 2020-03-26...
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, some of the parameters in the setting pages do not ensure text is the correct size for its buffer. Date published : 2020-03-26 https://www.us-cert.gov/ics/advisories/icsa-20-056-04
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. X-Force ID: 175984. Date published...
UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command. Date published : 2020-03-26 https://www.twcert.org.tw/tw/cp-132-3451-7d9f0-1.html
UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts information through a specific page. Date published : 2020-03-26 https://www.twcert.org.tw/tw/cp-132-3453-442a5-1.html
UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access the privileged page to manage accounts through specific system directory. Date published : 2020-03-26 https://www.twcert.org.tw/tw/cp-132-3452-937d6-1.html
HUAWEI smartphones P30 with versions earlier than 10.0.0.185(C00E85R1P11) have an improper access control vulnerability. The software incorrectly restricts access to a function interface from an unauthorized actor, the attacker tricks the user into installing...
A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and...
Osmand through 2.0.0 allow XXE because of binary/BinaryMapIndexReader.java. Date published : 2020-03-26 https://github.com/osmandapp/Osmand/issues/8711
Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java. Date published : 2020-03-26 https://github.com/azkaban/azkaban/issues/2478
Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java Date published : 2020-03-26 https://github.com/mulesoft/apikit/issues/547
An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component. Date published : 2020-03-26 https://github.com/Accenture/mercury/commit/f647a01347485d2afe3a0b735eab3d0121d61f46 https://github.com/Accenture/mercury/issues/13