|
210921
|
5.5 |
MEDIUM
Local
|
fig2dev_project
|
fig2dev
|
A global buffer overflow in the set_color component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ge format.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-21681
|
2024-11-21 14:12 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210922
|
5.5 |
MEDIUM
Local
|
fig2dev_project
|
fig2dev
|
A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21680
|
2024-11-21 14:12 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210923
|
5.5 |
MEDIUM
Local
|
fig2dev_project
|
fig2dev
|
A global buffer overflow in the genmp_writefontmacro_latex component in genmp.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into mp format.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-21678
|
2024-11-21 14:12 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210924
|
5.5 |
MEDIUM
Local
|
fig2dev_project debian
|
fig2dev debian_linux
|
A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21676
|
2024-11-21 14:12 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210925
|
5.5 |
MEDIUM
Local
|
fig2dev_project debian
|
fig2dev debian_linux
|
A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ptk format.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21675
|
2024-11-21 14:12 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210926
|
6.5 |
MEDIUM
Network
|
wagecms_project
|
wage-cms
|
A cross site request forgery (CSRF) in Wage-CMS 1.5.x-dev allows attackers to arbitrarily add users.
|
CWE-352
Origin Validation Error
|
CVE-2020-21358
|
2024-11-21 14:12 |
2021-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210927
|
6.1 |
MEDIUM
Network
|
popojicms
|
popojicms
|
A stored cross site scripting (XSS) vulnerability in /admin.php?mod=user&act=addnew of PopojiCMS 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the E-Mail fiel…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21357
|
2024-11-21 14:12 |
2021-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210928
|
5.3 |
MEDIUM
Network
|
popojicms
|
popojicms
|
An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file" is deleted during file uploads.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-21356
|
2024-11-21 14:12 |
2021-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210929
|
5.4 |
MEDIUM
Network
|
get-simple
|
getsimplecms
|
A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to execute arbitrary web scripts or HTML via crafted payload in the Edit Snippets mod…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21353
|
2024-11-21 14:12 |
2021-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210930
|
6.1 |
MEDIUM
Network
|
tidesec
|
wdscanner
|
Cross Site Scripting vulnerabiity exists in WDScanner 1.1 in the system management page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21854
|
2024-11-21 14:12 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|