|
211751
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. It allows attackers to execute arbitrary code via a Trojan horse taskkill.exe in the current working directory.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-26538
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211752
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
foxit_reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. In a certain Shading calculation, the number of outputs is unequal to the number of color components in a color space. This causes …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-26537
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211753
|
5.5 |
MEDIUM
Local
|
foxitsoftware
|
foxit_reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is a NULL pointer dereference via a crafted PDF document.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-26536
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211754
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
foxit_reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate thread local storage but obtains an unacceptable index value, V8 throws an exception that leads to…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-26535
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211755
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
foxit_reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::DeleteOptions, during AcroForm JavaScript execution.
|
CWE-416
Use After Free
|
CVE-2020-26534
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211756
|
5.3 |
MEDIUM
Network
|
filecloud
|
filecloud
|
CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.
|
NVD-CWE-noinfo
|
CVE-2020-26524
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211757
|
6.1 |
MEDIUM
Network
|
froala
|
froala_editor
|
Froala Editor before 3.2.2 allows XSS via pasted content.
|
CWE-79
Cross-site Scripting
|
CVE-2020-26523
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211758
|
- |
|
-
|
-
|
Dotmesh is a git-like command-line interface for capturing, organizing and sharing application states. In versions 0.8.1 and prior, the unsafe handling of symbolic links in an unpacking routine may
…
|
-
|
CVE-2020-26312
|
2024-11-21 14:19 |
2024-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211759
|
9.8 |
CRITICAL
Network
|
evenbalance
|
punkbuster
|
Directory Traversal vulnerability in Server functionalty in Even Balance Punkbuster version 1.902 before 1.905 allows remote attackers to execute arbitrary code.
|
CWE-22
Path Traversal
|
CVE-2020-26037
|
2024-11-21 14:19 |
2023-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211760
|
5.3 |
MEDIUM
Network
|
cisco
|
asyncos
|
A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are c…
|
NVD-CWE-noinfo
|
CVE-2020-26082
|
2024-11-21 14:19 |
2023-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|