|
209821
|
7.5 |
HIGH
Network
|
dovecot debian canonical fedoraproject
|
dovecot debian_linux ubuntu_linux fedora
|
In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-12673
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209822
|
8.1 |
HIGH
Network
|
gitlab
|
gitlab
|
In GitLab before 13.2.3, project sharing could temporarily allow too permissive access.
|
NVD-CWE-noinfo
|
CVE-2020-13291
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209823
|
7.2 |
HIGH
Network
|
gitlab
|
gitlab
|
In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page
|
CWE-287
Improper Authentication
|
CVE-2020-13290
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209824
|
4.8 |
MEDIUM
Network
|
gitlab
|
gitlab
|
In GitLab before 13.0.12, 13.1.6, and 13.2.3, a stored XSS vulnerability exists in the CI/CD Jobs page
|
CWE-79
Cross-site Scripting
|
CVE-2020-13288
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209825
|
6.1 |
MEDIUM
Network
|
rosariosis
|
student_information_system
|
Reflected Cross-Site Scripting vulnerability in Modules.php in RosarioSIS Student Information System < 6.5.1 allows remote attackers to execute arbitrary web script via embedding javascript or HTML t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13278
|
2024-11-21 14:00 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209826
|
5.5 |
MEDIUM
Local
|
teradici
|
graphics_agent pcoip_standard_agent
|
Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to 20.04.1 are not cleaned up in server memory, which may allow an attacker to read confiden…
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2020-13179
|
2024-11-21 14:00 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209827
|
6.7 |
MEDIUM
Local
|
teradici
|
graphics_agent pcoip_standard_agent
|
A function in the Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to version 20.04.1 does not properly validate the signature of an external binary, which could allow a…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-13178
|
2024-11-21 14:00 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209828
|
7.8 |
HIGH
Local
|
teradici
|
graphics_agent pcoip_standard_agent
|
The support bundler in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows versions prior to 20.04.1 and 20.07.0 does not use hard coded paths for certain Windows binaries, which…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-13177
|
2024-11-21 14:00 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209829
|
6.1 |
MEDIUM
Network
|
teradici
|
cloud_access_connector_legacy cloud_access_connector
|
The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 24, 2020 (v16 and earlier for the Cloud Access Connector) contains a stor…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13176
|
2024-11-21 14:00 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209830
|
7.5 |
HIGH
Network
|
teradici
|
cloud_access_connector_legacy cloud_access_connector
|
The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 20, 2020 (v15 and earlier for Cloud Access Connector) contains a local fi…
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2020-13175
|
2024-11-21 14:00 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|