|
198351
|
9.8 |
CRITICAL
Network
|
actix
|
actix-codec
|
An issue was discovered in the actix-codec crate before 0.3.0-beta.1 for Rust. There is a use-after-free in Framed.
|
CWE-416
Use After Free
|
CVE-2020-35902
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198352
|
7.5 |
HIGH
Network
|
actix
|
actix-http
|
An issue was discovered in the actix-http crate before 2.0.0-alpha.1 for Rust. There is a use-after-free in BodyStream.
|
CWE-416
Use After Free
|
CVE-2020-35901
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198353
|
5.5 |
MEDIUM
Local
|
array-queue_project
|
array-queue
|
An issue was discovered in the array-queue crate through 2020-09-26 for Rust. A pop_back() call may lead to a use-after-free.
|
CWE-416
Use After Free
|
CVE-2020-35900
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198354
|
5.5 |
MEDIUM
Local
|
actix
|
actix-service
|
An issue was discovered in the actix-service crate before 1.0.6 for Rust. The Cell implementation allows obtaining more than one mutable reference to the same data.
|
CWE-416
Use After Free
|
CVE-2020-35899
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198355
|
9.1 |
CRITICAL
Network
|
actix
|
actix-utils
|
An issue was discovered in the actix-utils crate before 2.0.0 for Rust. The Cell implementation allows obtaining more than one mutable reference to the same data.
|
CWE-416
Use After Free
|
CVE-2020-35898
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198356
|
9.8 |
CRITICAL
Network
|
hgiga
|
msr45_isherlock-user ssr45_isherlock-user
|
HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command inject attacks remotely and execute arbitrary commands of the system.
|
CWE-78
OS Command
|
CVE-2020-35851
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198357
|
7.5 |
HIGH
Network
|
mantisbt
|
mantisbt
|
An issue was discovered in MantisBT before 2.24.4. An incorrect access check in bug_revision_view_page.php allows an unprivileged attacker to view the Summary field of private issues, as well as bugn…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-35849
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198358
|
6.5 |
MEDIUM
Network
|
cockpit-project
|
cockpit
|
An SSRF issue was discovered in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-35850
|
2024-11-21 14:28 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198359
|
9.8 |
CRITICAL
Network
|
agentejo
|
cockpit
|
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
|
CWE-89
SQL Injection
|
CVE-2020-35848
|
2024-11-21 14:28 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198360
|
9.8 |
CRITICAL
Network
|
agentejo
|
cockpit
|
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
|
CWE-89
SQL Injection
|
CVE-2020-35847
|
2024-11-21 14:28 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|