|
210531
|
7.5 |
HIGH
Network
|
moddable
|
moddable
|
Invalid Memory Access in the fxProxyGetter function in moddable/xs/sources/xsProxy.c in Moddable SDK before OS200908 causes a denial of service (SEGV).
|
NVD-CWE-Other
|
CVE-2020-25461
|
2024-11-21 14:17 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210532
|
5.5 |
MEDIUM
Local
|
appimage
|
appimaged
|
AppImage appimaged before 1.0.3 does not properly check whether a downloaded file is a valid appimage. For example, it will accept a crafted mp3 file that contains an appimage, and install it.
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-25266
|
2024-11-21 14:17 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210533
|
6.5 |
MEDIUM
Network
|
appimage
|
libappimage
|
AppImage libappimage before 1.0.3 allows attackers to trigger an overwrite of a system-installed .desktop file by providing a .desktop file that contains Name= with path components.
|
NVD-CWE-noinfo
|
CVE-2020-25265
|
2024-11-21 14:17 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210534
|
8.8 |
HIGH
Network
|
we-con
|
plc_editor
|
WECON PLC Editor Versions 1.3.8 and prior has a heap-based buffer overflow vulnerabilities have been identified that may allow arbitrary code execution.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-25181
|
2024-11-21 14:17 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210535
|
8.8 |
HIGH
Network
|
we-con
|
plc_editor
|
WECON PLC Editor Versions 1.3.8 and prior has a stack-based buffer overflow vulnerability has been identified that may allow arbitrary code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-25177
|
2024-11-21 14:17 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210536
|
9.8 |
CRITICAL
Network
|
rtautomation
|
499es_ethernet\/ip_adaptor_firmware
|
499ES EtherNet/IP (ENIP) Adaptor Source Code is vulnerable to a stack-based buffer overflow, which may allow an attacker to send a specially crafted packet that may result in a denial-of-service cond…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-25159
|
2024-11-21 14:17 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210537
|
9.8 |
CRITICAL
Network
|
paradox
|
ip150_firmware
|
The affected product is vulnerable to three stack-based buffer overflows, which may allow an unauthenticated attacker to remotely execute arbitrary code on the IP150 (firmware versions 5.02.09).
|
-
|
CVE-2020-25189
|
2024-11-21 14:17 |
2020-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210538
|
8.8 |
HIGH
Network
|
paradox
|
ip150_firmware
|
The affected product is vulnerable to five post-authentication buffer overflows, which may allow a logged in user to remotely execute arbitrary code on the IP150 (firmware versions 5.02.09).
|
-
|
CVE-2020-25185
|
2024-11-21 14:17 |
2020-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210539
|
5.4 |
MEDIUM
Network
|
grocy_project
|
grocy
|
Cross-site Scripting (XSS) vulnerability in grocy 2.7.1 via the add recipe module, which gets executed when deleting the recipe.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25454
|
2024-11-21 14:17 |
2020-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210540
|
7.3 |
HIGH
Network
|
lemocms
|
lemocms
|
app\admin\controller\sys\Uploads.php in lemocms 1.8.x allows users to upload files to upload executable files.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-25406
|
2024-11-21 14:17 |
2020-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|