CVE-2020-1832
published 2020-05-29CVE-2020-1832: E6878-370 products with versions of 10.0.3.1(H557SP27C233) and 10.0.3.1(H563SP1C00) have a stack buffer overflow vulnerability. The program copies an input…
PriorityP344high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.48%
38.0th percentile
E6878-370 products with versions of 10.0.3.1(H557SP27C233) and 10.0.3.1(H563SP1C00) have a stack buffer overflow vulnerability. The program copies an input buffer to an output buffer without verification. An attacker in the adjacent network could send a crafted message, successful exploit could lead to stack buffer overflow which may cause malicious code execution.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | e6878-370 | — | — |
| huawei | e6878-370 | — | — |
| huawei | e6878-370_firmware | — | — |
| huawei | e6878-370_firmware | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:P
vendor_oracle9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f4fm-25px-642h: E6878-370 products with versions of 10
ghsa_unreviewed·2022-05-24
CVE-2020-1832 [MEDIUM] GHSA-f4fm-25px-642h: E6878-370 products with versions of 10
E6878-370 products with versions of 10.0.3.1(H557SP27C233) and 10.0.3.1(H563SP1C00) have a stack buffer overflow vulnerability. The program copies an input buffer to an output buffer without verification. An attacker in the adjacent network could send a crafted message, successful exploit could lead to stack buffer overflow which may cause malicious code execution.
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Platform (Apache Derby) — CVE-2015-1832
vendor_oracle·2020-10-15·CVSS 9.1
CVE-2015-1832 [CRITICAL] Oracle Oracle Construction and Engineering Risk Matrix: Platform (Apache Derby) — CVE-2015-1832
Oracle Oracle Construction and Engineering Risk Matrix: Platform (Apache Derby) vulnerability
CVE: CVE-2015-1832
CVSS: 9.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Knowledge Risk Matrix: Web Applications - InfoCenter (Apache Derby) — CVE-2015-1832
vendor_oracle·2020-04-15·CVSS 9.1
CVE-2015-1832 [CRITICAL] Oracle Oracle Knowledge Risk Matrix: Web Applications - InfoCenter (Apache Derby) — CVE-2015-1832
Oracle Oracle Knowledge Risk Matrix: Web Applications - InfoCenter (Apache Derby) vulnerability
CVE: CVE-2015-1832
CVSS: 9.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-05-29
Published