ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

10 results for “CVE-2020-1750”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-1750
Published
2021-06-07
CVSS:
6.5
ShadowTrackr CVSS:
5.4
Summary:
A flaw was found in the machine-config-operator that causes an OpenShift node to become unresponsive when a container consumes a large amount of memory. An attacker could use this flaw to deny access to schedule new pods in the OpenShift cluster. This was fixed in openshift/machine-config-operator 4.4.3, openshift/machine-config-operator 4.3.25, openshift/machine-config-operator 4.2.36.
CVE:
CVE-2020-17509
Published
2021-01-11
CVSS:
7.5
ShadowTrackr CVSS:
4.6
Summary:
ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.
CVE:
CVE-2020-17508
Published
2021-01-11
CVSS:
7.5
ShadowTrackr CVSS:
4.6
Summary:
The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.
CVE:
CVE-2020-17504
Published
2021-01-08
CVSS:
7.2
ShadowTrackr CVSS:
4.8
Summary:
The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users to the administration panel to perform authenticated remote code execution. An issue exists in ngpsystemcmd.php in which the http parameters "x_modules" and "y_modules" are not properly handled. The NDN-210 is part of Barco TransForm N solution and this vulnerability is patched from TransForm N version 3.8 onwards.
CVE:
CVE-2020-17503
Published
2021-01-08
CVSS:
7.2
ShadowTrackr CVSS:
4.8
Summary:
The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users to the administration panel to perform authenticated remote code execution. An issue exists in split_card_cmd.php in which the http parameter "locking" is not properly handled. The NDN-210 is part of Barco TransForm N solution and this vulnerability is patched from TransForm N version 3.8 onwards.
CVE:
CVE-2020-17502
Published
2021-01-08
CVSS:
7.2
ShadowTrackr CVSS:
4.8
Summary:
Barco TransForm N before 3.8 allows Command Injection (issue 2 of 4). The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users of the administration panel to perform authenticated remote code execution. An issue exists in split_card_cmd.php in which the http parameters xmodules, ymodules and savelocking are not properly handled. The NDN-210 is part of Barco TransForm N solution and includes the patch from TransForm N version 3.8 onwards.
CVE:
CVE-2020-17500
Published
2021-01-07
CVSS:
9.8
ShadowTrackr CVSS:
7.2
Summary:
Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of 4). The NDN-210 has a web administration panel which is made available over https. The logon method is basic authentication. There is a command injection issue that will result in unauthenticated remote code execution in the username and password fields of the logon prompt. The NDN-210 is part of Barco TransForm N solution and includes the patch from TransForm N version 3.8 onwards.
CVE:
CVE-2020-17507
Published
2020-08-12
CVSS:
5.3
ShadowTrackr CVSS:
2.9
Summary:
An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read.
CVE:
CVE-2020-17505
Published
2020-08-12
CVSS:
8.8
ShadowTrackr CVSS:
7.7
Summary:
Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_peform.
CVE:
CVE-2020-17506
Published
2020-08-12
CVSS:
9.8
ShadowTrackr CVSS:
9.2
Summary:
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.