|
199821
|
4.3 |
MEDIUM
Network
|
libslirp_project fedoraproject debian
|
libslirp fedora debian_linux
|
ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-29129
|
2024-11-21 14:23 |
2020-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199822
|
7.5 |
HIGH
Network
|
bigbluebutton
|
bigbluebutton
|
An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an e…
|
CWE-200
Information Exposure
|
CVE-2020-29043
|
2024-11-21 14:23 |
2020-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199823
|
3.7 |
LOW
Network
|
bigbluebutton
|
bigbluebutton
|
An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an access code.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-29042
|
2024-11-21 14:23 |
2020-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199824
|
9.8 |
CRITICAL
Network
|
petl_project
|
petl
|
petl before 1.68, in some configurations, allows resolution of entities in an XML document.
|
CWE-91
Blind XPath Injection
|
CVE-2020-29128
|
2024-11-21 14:23 |
2020-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199825
|
8.8 |
HIGH
Network
|
x11vnc_project fedoraproject debian
|
x11vnc fedora debian_linux
|
scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-29074
|
2024-11-21 14:23 |
2020-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199826
|
4.8 |
MEDIUM
Network
|
oscommerce
|
oscommerce
|
osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of newsletters.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29070
|
2024-11-21 14:23 |
2020-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199827
|
6.1 |
MEDIUM
Network
|
liquidfiles
|
liquidfiles
|
A Cross-Site Script Inclusion vulnerability was found on LiquidFiles before 3.3.19. This client-side attack requires user interaction (opening a link) and successful exploitation could lead to encryp…
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2020-29072
|
2024-11-21 14:23 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199828
|
9.0 |
CRITICAL
Network
|
liquidfiles
|
liquidfiles
|
An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19. The issue arises from the insecure rendering of HTML files uploaded to the platform as attachments, when the -htmlview URL i…
|
CWE-79
Cross-site Scripting
|
CVE-2020-29071
|
2024-11-21 14:23 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199829
|
5.5 |
MEDIUM
Local
|
modern_honey_network_project
|
modern_honey_network
|
_get_flag_ip_localdb in server/mhn/ui/utils.py in Modern Honey Network (MHN) through 2020-11-23 allows attackers to cause a denial-of-service via an IP address that is absent from a local geolocation…
|
NVD-CWE-noinfo
|
CVE-2020-29069
|
2024-11-21 14:23 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199830
|
7.5 |
HIGH
Network
|
cdatatec
|
72408a_firmware 9008a_firmware 9016a_firmware 92408a_firmware 92416a_firmware 9288_firmware 97016_firmware 97024p_firmware 97028p_firmware 97042p_firmware 97084p_firmwar…
|
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN,…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-29063
|
2024-11-21 14:23 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|