|
196631
|
8.8 |
HIGH
Network
|
frappe
|
erpnext
|
An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenti…
|
CWE-89
SQL Injection
|
CVE-2020-6145
|
2024-11-21 14:35 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196632
|
7.8 |
HIGH
Local
|
f2fs-tools_project fedoraproject
|
f2fs-tools fedora
|
An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A specially crafted f2fs file can cause a logic flaw and out-of-bounds heap operation…
|
CWE-131
Incorrect Calculation of Buffer Size
|
CVE-2020-6070
|
2024-11-21 14:35 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196633
|
7.5 |
HIGH
Network
|
freediameter
|
freediameter
|
An exploitable denial of service vulnerability exists in the freeDiameter functionality of freeDiameter 1.3.2. A specially crafted Diameter request can trigger a memory corruption resulting in denial…
|
CWE-787 CWE-191
Out-of-bounds Write Integer Underflow (Wrap or Wraparound)
|
CVE-2020-6098
|
2024-11-21 14:35 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196634
|
4.3 |
MEDIUM
Network
|
google debian opensuse fedoraproject
|
chrome debian_linux leap fedora backports_sle
|
Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to install a PWA to spoof the contents of the Omnibox (URL bar) via a crafted…
|
NVD-CWE-Other
|
CVE-2020-6536
|
2024-11-21 14:35 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196635
|
6.1 |
MEDIUM
Network
|
google opensuse debian fedoraproject
|
chrome backports_sle debian_linux leap fedora
|
Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a …
|
CWE-79
Cross-site Scripting
|
CVE-2020-6535
|
2024-11-21 14:35 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196636
|
8.8 |
HIGH
Network
|
google opensuse debian fedoraproject
|
chrome backports_sle debian_linux leap fedora
|
Heap buffer overflow in WebRTC in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6534
|
2024-11-21 14:35 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196637
|
8.8 |
HIGH
Network
|
google opensuse debian fedoraproject
|
chrome backports_sle debian_linux leap fedora
|
Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787 CWE-843
Out-of-bounds Write Type Confusion
|
CVE-2020-6533
|
2024-11-21 14:35 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196638
|
4.3 |
MEDIUM
Network
|
google debian opensuse fedoraproject
|
chrome debian_linux leap fedora backports_sle
|
Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-6531
|
2024-11-21 14:35 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196639
|
8.8 |
HIGH
Network
|
google opensuse fedoraproject debian
|
chrome leap backports_sle fedora debian_linux
|
Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6530
|
2024-11-21 14:35 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196640
|
4.3 |
MEDIUM
Network
|
google debian opensuse fedoraproject
|
chrome debian_linux leap fedora backports_sle
|
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-6529
|
2024-11-21 14:35 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|