|
210011
|
5.6 |
MEDIUM
Network
|
qemu canonical debian
|
qemu ubuntu_linux debian_linux
|
rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid memory copy operation.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13765
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210012
|
7.7 |
HIGH
Network
|
postgresql quarkus netapp fedoraproject debian
|
postgresql_jdbc_driver quarkus steelstore_cloud_integrated_storage fedora debian_linux
|
PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.
|
CWE-611
XXE
|
CVE-2020-13692
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210013
|
6.1 |
MEDIUM
Network
|
phplist
|
phplist
|
phpList before 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13827
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210014
|
7.7 |
HIGH
Network
|
indutny
|
elliptic
|
The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This could conceivably have a security-relevant impact…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-13822
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210015
|
7.5 |
HIGH
Network
|
foxitsoftware
|
reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows signature validation bypass via a modified file or a file with non-standard signatures.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-13810
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210016
|
7.5 |
HIGH
Network
|
foxitsoftware
|
reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via long strings in the content stream.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-13809
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210017
|
7.5 |
HIGH
Network
|
foxitsoftware
|
reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows resource consumption via crafted cross-reference stream data.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-13808
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210018
|
7.5 |
HIGH
Network
|
foxitsoftware
|
reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has circular reference mishandling that causes a loop.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-13807
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210019
|
7.5 |
HIGH
Network
|
foxitsoftware
|
reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has a use-after-free because of JavaScript execution after a deletion or close operation.
|
CWE-416
Use After Free
|
CVE-2020-13806
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210020
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has brute-force attack mishandling because the CAS service lacks a limit on login failures.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-13805
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|