|
199351
|
7.5 |
HIGH
Network
|
gnu redhat netapp
|
glibc enterprise_linux cloud_backup solidfire_baseboard_management_controller
|
sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer overflow if the input to any of the printf family of functions is an 80-bit long …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-29573
|
2024-11-21 14:24 |
2020-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199352
|
6.1 |
MEDIUM
Network
|
misp
|
misp
|
app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29572
|
2024-11-21 14:24 |
2020-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199353
|
6.1 |
MEDIUM
Network
|
openstack debian
|
horizon debian_linux
|
An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would all…
|
CWE-601
Open Redirect
|
CVE-2020-29565
|
2024-11-21 14:24 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199354
|
4.8 |
MEDIUM
Network
|
gnu fedoraproject netapp
|
glibc fedora e-series_santricity_os_controller
|
The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, …
|
CWE-617
Reachable Assertion
|
CVE-2020-29562
|
2024-11-21 14:24 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199355
|
5.5 |
MEDIUM
Local
|
boom-core
|
risvc-boom
|
An issue was discovered in SonicBOOM riscv-boom 3.0.0. For LR, it does not avoid acquiring a reservation in the case where a load translates successfully but still generates an exception.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-29561
|
2024-11-21 14:24 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199356
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
An issue was discovered in the Linux kernel before 5.9.3. io_uring takes a non-refcounted reference to the files_struct of the process that submitted a request, causing execve() to incorrectly optimi…
|
NVD-CWE-Other
|
CVE-2020-29534
|
2024-11-21 14:24 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199357
|
7.5 |
HIGH
Network
|
hashicorp
|
go-slug
|
HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed…
|
CWE-22 CWE-59
Path Traversal Link Following
|
CVE-2020-29529
|
2024-11-21 14:24 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199358
|
8.8 |
HIGH
Network
|
textpattern
|
textpattern
|
Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.
|
CWE-352
Origin Validation Error
|
CVE-2020-29458
|
2024-11-21 14:24 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199359
|
4.3 |
MEDIUM
Network
|
umbraco
|
umbraco_cms
|
Editors/LogViewerController.cs in Umbraco through 8.9.1 allows a user to visit a logviewer endpoint even if they lack Applications.Settings access.
|
CWE-863
Incorrect Authorization
|
CVE-2020-29454
|
2024-11-21 14:24 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199360
|
6.1 |
MEDIUM
Network
|
papermerge
|
papermerge
|
Multiple cross-site scripting (XSS) vulnerabilities in Papermerge before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the rename, tag, upload, or create folder function. Th…
|
CWE-79
Cross-site Scripting
|
CVE-2020-29456
|
2024-11-21 14:24 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|