ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

7 results for “CVE-2020-3548”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-3548
Published
2024-11-18
CVSS:
5.3
ShadowTrackr CVSS:
1.7
Summary:
A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to inefficient processing of incoming TLS traffic. An attacker could exploit this vulnerability by sending a series of crafted TLS packets to an affected device. A successful exploit could allow the attacker to trigger a prolonged state of high CPU utilization. The affected device would still be operative, but response time and overall performance may be degraded.There are no workarounds that address this vulnerability.
CVE:
CVE-2020-35482
Published
2021-02-03
CVSS:
5.4
ShadowTrackr CVSS:
0.4
Summary:
SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS.
CVE:
CVE-2020-35481
Published
2021-02-03
CVSS:
9.8
ShadowTrackr CVSS:
7.2
Summary:
SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.
CVE:
CVE-2020-35483
Published
2021-01-11
CVSS:
7.8
ShadowTrackr CVSS:
4.0
Summary:
AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local user account via a read-only setting for a Trojan horse gcapi.dll file.
CVE:
CVE-2020-35488
Published
2021-01-05
CVSS:
7.5
ShadowTrackr CVSS:
6.9
Summary:
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a crafted Syslog payload to the Syslog service. This attack requires a specific configuration. Also, the name of the directory created must use a Syslog field. (For example, on Linux it is not possible to create a .. directory. On Windows, it is not possible to create a CON directory.)
CVE:
CVE-2020-35480
Published
2020-12-18
CVSS:
5.3
ShadowTrackr CVSS:
1.7
Summary:
An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently, exposing sensitive information about the hidden status to unprivileged viewers. This exists on various code paths.
CVE:
CVE-2020-35489
Published
2020-12-17
CVSS:
10.0
ShadowTrackr CVSS:
8.2
Summary:
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.