|
199021
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1. A malicious application may be able to read restricted memory.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-29629
|
2024-11-21 14:24 |
2021-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199022
|
7.5 |
HIGH
Network
|
apple
|
mac_os_x
|
A race condition was addressed with additional validation. This issue is fixed in Security Update 2021-005 Catalina. Mounting a maliciously crafted NFS network share may lead to arbitrary code execut…
|
CWE-362
Race Condition
|
CVE-2020-29622
|
2024-11-21 14:24 |
2021-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199023
|
8.1 |
HIGH
Network
|
smartertools
|
smartermail
|
An issue was discovered in SmarterTools SmarterMail through 100.0.7537. Meddler-in-the-middle attackers can pipeline commands after a POP3 STLS command, injecting plaintext commands into an encrypted…
|
CWE-77
Command Injection
|
CVE-2020-29548
|
2024-11-21 14:24 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199024
|
4.4 |
MEDIUM
Local
|
dell
|
emc_powerstore
|
Dell EMC PowerStore versions prior to 1.0.3.0.5.xxx contain a file permission Vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the information …
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-29503
|
2024-11-21 14:24 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199025
|
6.7 |
MEDIUM
Local
|
dell
|
emc_powerstore
|
Dell EMC PowerStore versions prior to 1.0.3.0.5.006 contain an OS Command Injection vulnerability in PowerStore X environment . A locally authenticated attacker could potentially exploit this vulnera…
|
CWE-78
OS Command
|
CVE-2020-29499
|
2024-11-21 14:24 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199026
|
4.3 |
MEDIUM
Network
|
atlassian
|
confluence_server
|
Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 before 7.11.0 allow attackers to identify internal hosts and ports via a blind server-side request forgery vulnerability i…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-29445
|
2024-11-21 14:24 |
2021-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199027
|
5.4 |
MEDIUM
Network
|
atlassian
|
confluence_server confluence_data_center
|
Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting Vulnerability in admin global setting parameter…
|
CWE-79
Cross-site Scripting
|
CVE-2020-29444
|
2024-11-21 14:24 |
2021-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199028
|
5.4 |
MEDIUM
Network
|
orchardproject
|
orchard
|
An issue was discovered in Orchard before 1.10. The Media Settings Allowed File Types list field allows an attacker to add a XSS payload that will execute when users attempt to upload a disallowed fi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-29593
|
2024-11-21 14:24 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199029
|
9.8 |
CRITICAL
Network
|
orchardproject
|
orchard
|
An issue was discovered in Orchard before 1.10. A broken access control issue in Orchard components that use the TinyMCE HTML editor's file upload allows an attacker to upload dangerous executables t…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-29592
|
2024-11-21 14:24 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199030
|
5.5 |
MEDIUM
Local
|
apple
|
iphone_os ipados
|
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0. Processing a maliciously crafted font may result in the disclosure of process memo…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-29639
|
2024-11-21 14:24 |
2021-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|