|
210251
|
7.5 |
HIGH
Network
|
avast
|
antivirus
|
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to trigger a shutdown via RPC from a Low Int…
|
NVD-CWE-noinfo
|
CVE-2020-10863
|
2024-11-21 13:56 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210252
|
7.8 |
HIGH
Local
|
avast
|
antivirus
|
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to achieve Local Privilege Escalation (LPE) …
|
NVD-CWE-noinfo
|
CVE-2020-10862
|
2024-11-21 13:56 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210253
|
7.5 |
HIGH
Network
|
avast
|
antivirus
|
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to achieve Arbitrary File Deletion from Avas…
|
NVD-CWE-noinfo
|
CVE-2020-10861
|
2024-11-21 13:56 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210254
|
7.5 |
HIGH
Network
|
avast
|
antivirus
|
An issue was discovered in Avast Antivirus before 20. An Arbitrary Memory Address Overwrite vulnerability in the aswAvLog Log Library results in Denial of Service of the Avast Service (AvastSvc.exe).
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10860
|
2024-11-21 13:56 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210255
|
8.8 |
HIGH
Network
|
fasterxml debian netapp oracle
|
jackson-databind debian_linux steelstore_cloud_integrated_storage retail_xstore_point_of_service primavera_unifier retail_service_backbone weblogic_server webcenter_portal ret…
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-11113
|
2024-11-21 13:56 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210256
|
8.8 |
HIGH
Network
|
fasterxml debian netapp oracle
|
jackson-databind debian_linux steelstore_cloud_integrated_storage retail_xstore_point_of_service primavera_unifier retail_service_backbone weblogic_server retail_merchandising_sy…
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commo…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-11112
|
2024-11-21 13:56 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210257
|
8.8 |
HIGH
Network
|
fasterxml debian netapp oracle
|
jackson-databind debian_linux steelstore_cloud_integrated_storage retail_xstore_point_of_service primavera_unifier weblogic_server retail_merchandising_system agile_plm bankin…
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, a…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-11111
|
2024-11-21 13:56 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210258
|
6.1 |
MEDIUM
Network
|
tecrail
|
responsive_filemanager
|
An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION['RF']["view_type"] wasn't sanitized if it was already set. This made stored XS…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11106
|
2024-11-21 13:56 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210259
|
9.8 |
CRITICAL
Network
|
usc
|
cereal
|
An issue was discovered in USC iLab cereal through 1.3.0. It employs caching of std::shared_ptr values, using the raw pointer address as a unique identifier. This becomes problematic if an std::share…
|
CWE-763
Release of Invalid Pointer or Reference
|
CVE-2020-11105
|
2024-11-21 13:56 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210260
|
5.3 |
MEDIUM
Network
|
usc
|
cereal
|
An issue was discovered in USC iLab cereal through 1.3.0. Serialization of an (initialized) C/C++ long double variable into a BinaryArchive or PortableBinaryArchive leaks several bytes of stack or he…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2020-11104
|
2024-11-21 13:56 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|