|
198081
|
5.5 |
MEDIUM
Local
|
libraw debian
|
libraw debian_linux
|
In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35530
|
2024-11-21 14:27 |
2022-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198082
|
9.8 |
CRITICAL
Network
|
sqlite netapp
|
sqlite ontap_select_deploy_administration_utility
|
In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.
|
-
|
CVE-2020-35527
|
2024-11-21 14:27 |
2022-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198083
|
7.5 |
HIGH
Network
|
sqlite
|
sqlite
|
In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-35525
|
2024-11-21 14:27 |
2022-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198084
|
5.5 |
MEDIUM
Local
|
libjpeg-turbo
|
libjpeg-turbo
|
A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-35538
|
2024-11-21 14:27 |
2022-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198085
|
7.8 |
HIGH
Local
|
libpng debian
|
pngcheck debian_linux
|
A global buffer overflow was discovered in pngcheck function in pngcheck-2.4.0(5 patches applied) via a crafted png file.
|
-
|
CVE-2020-35511
|
2024-11-21 14:27 |
2022-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198086
|
5.4 |
MEDIUM
Network
|
redhat
|
keycloak
|
A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest th…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-35509
|
2024-11-21 14:27 |
2022-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198087
|
6.1 |
MEDIUM
Network
|
gollum_project
|
gollum
|
Cross site scripting (XSS) in gollum 5.0 to 5.1.2 via the filename parameter to the 'New Page' dialog.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35305
|
2024-11-21 14:27 |
2022-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198088
|
5.4 |
MEDIUM
Network
|
multi_restaurant_table_reservation_system_project
|
multi_restaurant_table_reservation_system
|
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Restaurant Name field to /dashboard/profile.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35261
|
2024-11-21 14:27 |
2022-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198089
|
8.8 |
HIGH
Network
|
victor_cms_project
|
victor_cms
|
Victor CMS 1.0 is vulnerable to SQL injection via c_id parameter of admin_edit_comment.php, p_id parameter of admin_edit_post.php, u_id parameter of admin_edit_user.php, and edit parameter of admin_u…
|
CWE-89
SQL Injection
|
CVE-2020-35597
|
2024-11-21 14:27 |
2022-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198090
|
8.8 |
HIGH
Network
|
cgal debian
|
computational_geometry_algorithms_library debian_linux
|
Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
|
-
|
CVE-2020-35632
|
2024-11-21 14:27 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|