|
197151
|
6.5 |
MEDIUM
Network
|
freerdp fedoraproject opensuse canonical debian
|
freerdp fedora leap ubuntu_linux debian_linux
|
In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with sessions with color depth < 32 are affected. This is fixed in version 2.1.2.
|
-
|
CVE-2020-4033
|
2024-11-21 14:32 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197152
|
4.3 |
MEDIUM
Network
|
freerdp opensuse fedoraproject canonical debian
|
freerdp leap fedora ubuntu_linux debian_linux
|
In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1…
|
-
|
CVE-2020-4032
|
2024-11-21 14:32 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197153
|
7.5 |
HIGH
Network
|
freerdp fedoraproject opensuse canonical debian
|
freerdp fedora leap ubuntu_linux debian_linux
|
In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility mode with /relax-order-checks are affected. This is fixed in version 2.1.2.
|
-
|
CVE-2020-4031
|
2024-11-21 14:32 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197154
|
6.5 |
MEDIUM
Network
|
freerdp fedoraproject opensuse canonical debian
|
freerdp fedora leap ubuntu_linux debian_linux
|
In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.
|
-
|
CVE-2020-4030
|
2024-11-21 14:32 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197155
|
5.4 |
MEDIUM
Network
|
w3c
|
css_validator
|
In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validator link to trigger i…
|
-
|
CVE-2020-4070
|
2024-11-21 14:32 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197156
|
9.8 |
CRITICAL
Network
|
apnswift_project
|
apnswift
|
In APNSwift 1.0.0, calling APNSwiftSigner.sign(digest:) is likely to result in a heap buffer overflow. This has been fixed in 1.0.1.
|
-
|
CVE-2020-4068
|
2024-11-21 14:32 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197157
|
7.2 |
HIGH
Network
|
limdu_project
|
limdu
|
In Limdu before 0.95, the trainBatch function has a command injection vulnerability. Clients of the Limdu library are unlikely to be aware of this, so they might unwittingly write code that contains …
|
-
|
CVE-2020-4066
|
2024-11-21 14:32 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197158
|
9.0 |
CRITICAL
Adjacent
|
cyberark
|
conjur_oss_helm_chart
|
In Conjur OSS Helm Chart before 2.0.0, a recently identified critical vulnerability resulted in the installation of the Conjur Postgres database with an open port. This allows an attacker to gain ful…
|
NVD-CWE-Other
|
CVE-2020-4062
|
2024-11-21 14:32 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197159
|
5.0 |
MEDIUM
Network
|
semtech
|
lora_basics_station
|
In LoRa Basics Station before 2.0.4, there is a Use After Free vulnerability that leads to memory corruption. This bug is triggered on 32-bit machines when the CUPS server responds with a message (ht…
|
-
|
CVE-2020-4060
|
2024-11-21 14:32 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197160
|
3.3 |
LOW
Local
|
vmware
|
tools
|
VMware Tools for macOS (11.x.x and prior before 11.1.1) contains a denial-of-service vulnerability in the Host-Guest File System (HGFS) implementation. Successful exploitation of this issue may allow…
|
NVD-CWE-noinfo
|
CVE-2020-3972
|
2024-11-21 14:32 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|