
Look up vulnerabilities by software, product or CVE number.
| CVE | Published | CVSS | ShadowTrackr CVSS | Summary |
|---|---|---|---|---|
CVE: CVE-2020-1750 | Published 2021-06-07 | CVSS: 6.5 | ShadowTrackr CVSS: 5.4 | Summary: A flaw was found in the machine-config-operator that causes an OpenShift node to become unresponsive when a container consumes a large amount of memory. An attacker could use this flaw to deny access to schedule new pods in the OpenShift cluster. This was fixed in openshift/machine-config-operator 4.4.3, openshift/machine-config-operator 4.3.25, openshift/machine-config-operator 4.2.36. |
CVE: CVE-2020-17509 | Published 2021-01-11 | CVSS: 7.5 | ShadowTrackr CVSS: 4.6 | Summary: ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected. |
CVE: CVE-2020-17508 | Published 2021-01-11 | CVSS: 7.5 | ShadowTrackr CVSS: 4.6 | Summary: The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected. |
CVE: CVE-2020-17504 | Published 2021-01-08 | CVSS: 7.2 | ShadowTrackr CVSS: 4.8 | Summary: The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users to the administration panel to perform authenticated remote code execution. An issue exists in ngpsystemcmd.php in which the http parameters "x_modules" and "y_modules" are not properly handled. The NDN-210 is part of Barco TransForm N solution and this vulnerability is patched from TransForm N version 3.8 onwards. |
CVE: CVE-2020-17503 | Published 2021-01-08 | CVSS: 7.2 | ShadowTrackr CVSS: 4.8 | Summary: The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users to the administration panel to perform authenticated remote code execution. An issue exists in split_card_cmd.php in which the http parameter "locking" is not properly handled. The NDN-210 is part of Barco TransForm N solution and this vulnerability is patched from TransForm N version 3.8 onwards. |
CVE: CVE-2020-17502 | Published 2021-01-08 | CVSS: 7.2 | ShadowTrackr CVSS: 4.8 | Summary: Barco TransForm N before 3.8 allows Command Injection (issue 2 of 4). The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users of the administration panel to perform authenticated remote code execution. An issue exists in split_card_cmd.php in which the http parameters xmodules, ymodules and savelocking are not properly handled. The NDN-210 is part of Barco TransForm N solution and includes the patch from TransForm N version 3.8 onwards. |
CVE: CVE-2020-17500 | Published 2021-01-07 | CVSS: 9.8 | ShadowTrackr CVSS: 7.2 | Summary: Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of 4). The NDN-210 has a web administration panel which is made available over https. The logon method is basic authentication. There is a command injection issue that will result in unauthenticated remote code execution in the username and password fields of the logon prompt. The NDN-210 is part of Barco TransForm N solution and includes the patch from TransForm N version 3.8 onwards. |
CVE: CVE-2020-17507 | Published 2020-08-12 | CVSS: 5.3 | ShadowTrackr CVSS: 2.9 | Summary: An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read. |
CVE: CVE-2020-17505 | Published 2020-08-12 | CVSS: 8.8 | ShadowTrackr CVSS: 7.7 | Summary: Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_peform. |
CVE: CVE-2020-17506 | Published 2020-08-12 | CVSS: 9.8 | ShadowTrackr CVSS: 9.2 | Summary: Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php. |