|
197721
|
5.3 |
MEDIUM
Network
|
veritas
|
desktop_and_laptop_option
|
Veritas Desktop and Laptop Option (DLO) before 9.5 disclosed operational information on the backup processing status through a URL that did not require authentication.
|
NVD-CWE-noinfo
|
CVE-2020-36159
|
2024-11-21 14:28 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197722
|
6.7 |
MEDIUM
Local
|
linux fedoraproject debian netapp
|
linux_kernel fedora debian_linux cloud_backup solidfire_baseboard_management_controller_firmware
|
mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-36158
|
2024-11-21 14:28 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197723
|
9.8 |
CRITICAL
Network
|
ultimatemember
|
ultimate_member
|
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles. Due to the lack of filtering on the role parameter that cou…
|
NVD-CWE-noinfo
|
CVE-2020-36157
|
2024-11-21 14:28 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197724
|
8.8 |
HIGH
Network
|
ultimatemember
|
ultimate_member
|
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Authenticated Privilege Escalation via Profile Update. Any user with wp-admin access to the profile.php page cou…
|
CWE-269
Improper Privilege Management
|
CVE-2020-36156
|
2024-11-21 14:28 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197725
|
9.8 |
CRITICAL
Network
|
ultimatemember
|
ultimate_member
|
An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Meta. An attacker could supply an array parameter for sensitive me…
|
CWE-269
Improper Privilege Management
|
CVE-2020-36155
|
2024-11-21 14:28 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197726
|
7.8 |
HIGH
Local
|
pearson
|
vue_testing_system
|
The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE" directory, which allows local users to obtain administrative…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-36154
|
2024-11-21 14:28 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197727
|
9.8 |
CRITICAL
Network
|
cse_bookstore_project
|
cse_bookstore
|
CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php and in cart.php. A successful exploitation of th…
|
CWE-89
SQL Injection
|
CVE-2020-36112
|
2024-11-21 14:28 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197728
|
7.5 |
HIGH
Network
|
ffmpeg debian
|
ffmpeg debian_linux
|
decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35965
|
2024-11-21 14:28 |
2021-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197729
|
6.5 |
MEDIUM
Network
|
ffmpeg
|
ffmpeg
|
track_header in libavformat/vividas.c in FFmpeg 4.3.1 has an out-of-bounds write because of incorrect extradata packing.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35964
|
2024-11-21 14:28 |
2021-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197730
|
7.8 |
HIGH
Local
|
treasuredata
|
fluent_bit
|
flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correct calculation of the maximum gzip data-size expansion.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35963
|
2024-11-21 14:28 |
2021-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|