|
197471
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to avoid potential deadlock
Using f2fs_trylock_op() in f2fs_write_compressed_pages() to avoid potential
deadlock like w…
|
CWE-667
Improper Locking
|
CVE-2020-36775
|
2024-11-21 14:30 |
2024-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197472
|
- |
|
-
|
-
|
plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox, leading to a denial of service (application crash).
|
-
|
CVE-2020-36774
|
2024-11-21 14:30 |
2024-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197473
|
9.8 |
CRITICAL
Network
|
artifex
|
ghostscript
|
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one …
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2020-36773
|
2024-11-21 14:30 |
2024-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197474
|
4.4 |
MEDIUM
Local
|
cloudlinux
|
cagefs
|
CloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allows local users to read and write arbitrary files of certain file formats outsid…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2020-36772
|
2024-11-21 14:30 |
2024-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197475
|
7.8 |
HIGH
Local
|
cloudlinux
|
cagefs
|
CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication token via the process list and…
|
NVD-CWE-noinfo
|
CVE-2020-36771
|
2024-11-21 14:30 |
2024-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197476
|
9.8 |
CRITICAL
Network
|
gentoo
|
ebuild_for_slurm
|
pkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root filesystem. This could be exploited by the slurm user to bec…
|
NVD-CWE-noinfo
|
CVE-2020-36770
|
2024-11-21 14:30 |
2024-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197477
|
9.8 |
CRITICAL
Network
|
reiner-lemoine-institut
|
nesp2
|
A vulnerability was found in rl-institut NESP2 Initial Release/1.0. It has been classified as critical. Affected is an unknown function of the file app/database.py. The manipulation leads to sql inje…
|
-
|
CVE-2020-36768
|
2024-11-21 14:30 |
2023-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197478
|
7.5 |
HIGH
Network
|
vareille
|
tinyfiledialogs
|
tinyfiledialogs (aka tiny file dialogs) before 3.8.0 allows shell metacharacters in titles, messages, and other input data.
|
NVD-CWE-noinfo
|
CVE-2020-36767
|
2024-11-21 14:30 |
2023-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197479
|
5.4 |
MEDIUM
Network
|
duxcms_project
|
duxcms
|
Cross Site Scripting (XSS) vulnerability in DuxCMS 2.1 allows remote attackers to run arbitrary code via the content, time, copyfrom parameters when adding or editing a post.
|
CWE-79
Cross-site Scripting
|
CVE-2020-36763
|
2024-11-21 14:30 |
2023-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197480
|
9.8 |
CRITICAL
Network
|
ons
|
ras_collection_instrument
|
A vulnerability was found in ONS Digital RAS Collection Instrument up to 2.0.27 and classified as critical. Affected by this issue is the function jobs of the file .github/workflows/comment.yml. The …
|
-
|
CVE-2020-36762
|
2024-11-21 14:30 |
2023-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|