|
197911
|
5.3 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center jira_server
|
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile s…
|
NVD-CWE-noinfo
|
CVE-2020-36235
|
2024-11-21 14:29 |
2021-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197912
|
4.8 |
MEDIUM
Network
|
atlassian
|
jira data_center jira_server jira_data_center
|
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view. The …
|
CWE-79
Cross-site Scripting
|
CVE-2020-36234
|
2024-11-21 14:29 |
2021-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197913
|
9.8 |
CRITICAL
Network
|
genivi debian
|
diagnostic_log_and_trace debian_linux
|
The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an attacker to remotely execute arbitrary code on the DLT-Daemon (versions prior to…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-36244
|
2024-11-21 14:29 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197914
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can send a POST request t…
|
CWE-78
OS Command
|
CVE-2020-36243
|
2024-11-21 14:29 |
2021-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197915
|
9.1 |
CRITICAL
Network
|
cryptography.io fedoraproject oracle
|
cryptography fedora communications_cloud_native_core_network_function_cloud_native_environment
|
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrate…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2020-36242
|
2024-11-21 14:29 |
2021-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197916
|
5.5 |
MEDIUM
Local
|
gnome fedoraproject
|
gnome-autoar fedora
|
autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's…
|
CWE-22 CWE-59
Path Traversal Link Following
|
CVE-2020-36241
|
2024-11-21 14:29 |
2021-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197917
|
4.3 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnera…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-36231
|
2024-11-21 14:29 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197918
|
7.5 |
HIGH
Network
|
openldap debian apple apache
|
openldap debian_linux mac_os_x macos bookkeeper
|
A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.
|
CWE-617
Reachable Assertion
|
CVE-2020-36230
|
2024-11-21 14:29 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197919
|
7.5 |
HIGH
Network
|
openldap debian apple
|
openldap debian_linux mac_os_x macos
|
A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service.
|
CWE-843
Type Confusion
|
CVE-2020-36229
|
2024-11-21 14:29 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197920
|
7.5 |
HIGH
Network
|
openldap debian apple
|
openldap debian_linux macos
|
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service.
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2020-36228
|
2024-11-21 14:29 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|