|
198261
|
7.5 |
HIGH
Network
|
ffmpeg debian
|
ffmpeg debian_linux
|
decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35965
|
2024-11-21 14:28 |
2021-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198262
|
6.5 |
MEDIUM
Network
|
ffmpeg
|
ffmpeg
|
track_header in libavformat/vividas.c in FFmpeg 4.3.1 has an out-of-bounds write because of incorrect extradata packing.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35964
|
2024-11-21 14:28 |
2021-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198263
|
7.8 |
HIGH
Local
|
treasuredata
|
fluent_bit
|
flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correct calculation of the maximum gzip data-size expansion.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35963
|
2024-11-21 14:28 |
2021-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198264
|
7.5 |
HIGH
Network
|
loopring
|
loopring
|
The sellTokenForLRC function in the vault protocol in the smart contract implementation for Loopring (LRC), an Ethereum token, lacks access control for fee swapping and thus allows price manipulation.
|
NVD-CWE-noinfo
|
CVE-2020-35962
|
2024-11-21 14:28 |
2021-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198265
|
6.5 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish between incorrect username and incorrect password (i.e., not a single "Incorrect user…
|
NVD-CWE-noinfo
|
CVE-2020-35952
|
2024-11-21 14:28 |
2021-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198266
|
9.9 |
CRITICAL
Network
|
expresstech
|
quiz_and_survey_master
|
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offl…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-35951
|
2024-11-21 14:28 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198267
|
8.8 |
HIGH
Network
|
xcloner
|
xcloner
|
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).
|
CWE-352
Origin Validation Error
|
CVE-2020-35950
|
2024-11-21 14:28 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198268
|
9.8 |
CRITICAL
Network
|
expresstech
|
quiz_and_survey_master
|
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution.…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-35949
|
2024-11-21 14:28 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198269
|
8.8 |
HIGH
Network
|
xcloner
|
xcloner
|
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so woul…
|
CWE-863
Incorrect Authorization
|
CVE-2020-35948
|
2024-11-21 14:28 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198270
|
7.4 |
HIGH
Network
|
pagelayer
|
pagelayer
|
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authentic…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35947
|
2024-11-21 14:28 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|