|
209551
|
5.5 |
MEDIUM
Local
|
broadcom
|
tcpreplay
|
Buffer Overflow in Tcpreplay v4.3.2 allows attackers to cause a Denial of Service via the 'do_checksum' function in 'checksum.c'. It can be triggered by sending a crafted pcap file to the 'tcpreplay-…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-18976
|
2024-11-21 14:08 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209552
|
3.3 |
LOW
Local
|
nasm
|
netwide_assembler
|
Buffer Overflow in Netwide Assembler (NASM) v2.15.xx allows attackers to cause a denial of service via 'crc64i' in the component 'nasmlib/crc64'. This issue is different than CVE-2019-7147.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-18974
|
2024-11-21 14:08 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209553
|
5.5 |
MEDIUM
Local
|
podofo_project
|
podofo
|
Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-18972
|
2024-11-21 14:08 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209554
|
5.5 |
MEDIUM
Local
|
podofo_project
|
podofo
|
Stack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component 'src/base/PdfDictionary.cpp:65'.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-18971
|
2024-11-21 14:08 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209555
|
8.8 |
HIGH
Network
|
dedecms
|
dedecms
|
The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.
|
CWE-352
Origin Validation Error
|
CVE-2020-18917
|
2024-11-21 14:08 |
2021-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209556
|
7.5 |
HIGH
Network
|
ecisp
|
espcms-p8
|
EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array parameter. This vulnerability allows attackers to access sensitive…
|
CWE-89
SQL Injection
|
CVE-2020-18913
|
2024-11-21 14:08 |
2021-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209557
|
6.5 |
MEDIUM
Network
|
libav
|
libav
|
In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_p_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-18778
|
2024-11-21 14:08 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209558
|
6.5 |
MEDIUM
Network
|
libav
|
libav
|
In Libav 12.3, there is a segmentation fault in vc1_decode_b_mb_intfr in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-18776
|
2024-11-21 14:08 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209559
|
6.5 |
MEDIUM
Network
|
libav
|
libav
|
In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_b_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-18775
|
2024-11-21 14:08 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209560
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.
|
CWE-369
Divide By Zero
|
CVE-2020-18774
|
2024-11-21 14:08 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|