|
199531
|
9.8 |
CRITICAL
Network
|
struct2json_project
|
struct2json
|
struct2json before 2020-11-18 is affected by a Buffer Overflow because strcpy is used for S2J_STRUCT_GET_string_ELEMENT.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-29203
|
2024-11-21 14:23 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199532
|
5.5 |
MEDIUM
Local
|
tengine_project
|
tengine
|
The serializer module in OAID Tengine lite-v1.0 has a Buffer Overflow and crash. NOTE: another person has stated "I don't think there is an proof of overflow so far.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-28759
|
2024-11-21 14:23 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199533
|
6.1 |
MEDIUM
Network
|
litespeedtech
|
litespeed_cache
|
A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.
|
CWE-79
Cross-site Scripting
|
CVE-2020-29172
|
2024-11-21 14:23 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199534
|
5.5 |
MEDIUM
Local
|
gnome canonical fedoraproject
|
gdk-pixbuf ubuntu_linux fedora
|
GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign t…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-29385
|
2024-11-21 14:23 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199535
|
4.8 |
MEDIUM
Network
|
wondercms
|
wondercms
|
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in Page keywords and each time any user will visit the website, the XSS triggers, …
|
CWE-79
Cross-site Scripting
|
CVE-2020-29247
|
2024-11-21 14:23 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199536
|
7.0 |
HIGH
Local
|
mariadb
|
mariadb
|
With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the n…
|
NVD-CWE-Other
|
CVE-2020-28912
|
2024-11-21 14:23 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199537
|
8.1 |
HIGH
Network
|
terra-master
|
tos
|
Incorrect Access Control vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated attackers to bypass read-only restriction and obtain full access to any folder within the NAS
|
NVD-CWE-noinfo
|
CVE-2020-29189
|
2024-11-21 14:23 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199538
|
7.1 |
HIGH
Local
|
malwarebytes
|
malwarebytes endpoint_protection
|
In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.
|
CWE-59
Link Following
|
CVE-2020-28641
|
2024-11-21 14:23 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199539
|
8.8 |
HIGH
Network
|
odoo
|
odoo
|
A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated users to execute arbitrary code, leadi…
|
NVD-CWE-noinfo
|
CVE-2020-29396
|
2024-11-21 14:23 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199540
|
6.5 |
MEDIUM
Network
|
sonatype
|
nexus_repository_manager
|
Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.…
|
CWE-611
XXE
|
CVE-2020-29436
|
2024-11-21 14:23 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|