|
197211
|
8.8 |
HIGH
Network
|
accusoft
|
imagegear
|
An exploitable out-of-bounds write vulnerability exists in the ico_read function of the igcore19d.dll library of Accusoft ImageGear 19.6.0. A specially crafted ICO file can cause an out-of-bounds wri…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6082
|
2024-11-21 14:35 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197212
|
8.8 |
HIGH
Network
|
accusoft
|
imagegear
|
An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll ICO icoread parser of the Accusoft ImageGear 19.5.0 library. A specially crafted ICO file can cause an out-of-bounds write…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6076
|
2024-11-21 14:35 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197213
|
8.8 |
HIGH
Network
|
accusoft
|
imagegear
|
An exploitable out-of-bounds write vulnerability exists in the store_data_buffer function of the igcore19d.dll library of Accusoft ImageGear 19.5.0. A specially crafted PNG file can cause an out-of-b…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6075
|
2024-11-21 14:35 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197214
|
6.1 |
MEDIUM
Network
|
sap
|
netweaver_as_abap_business_server_pages
|
SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, is vulnerable to reflected Cross-Site Scripting (XSS) via …
|
CWE-79
Cross-site Scripting
|
CVE-2020-6213
|
2024-11-21 14:35 |
2020-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197215
|
5.4 |
MEDIUM
Network
|
sap
|
erp s\/4hana
|
Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and S/4 HANA (versions 100, 101, 102, 103, 104) do no…
|
CWE-862
Missing Authorization
|
CVE-2020-6212
|
2024-11-21 14:35 |
2020-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197216
|
6.1 |
MEDIUM
Network
|
sap
|
netweaver_as_abap_business_server_pages
|
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in re…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6217
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197217
|
6.1 |
MEDIUM
Network
|
sap
|
netweaver_as_abap_business_server_pages
|
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insu…
|
CWE-601
Open Redirect
|
CVE-2020-6215
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197218
|
6.1 |
MEDIUM
Network
|
sap
|
businessobjects_business_intelligence_platform
|
SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials …
|
CWE-601
Open Redirect
|
CVE-2020-6211
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197219
|
9.8 |
CRITICAL
Network
|
sap
|
businessobjects_business_intelligence_platform
|
SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclosure. It involves social engineering in order to ga…
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2020-6195
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197220
|
9.3 |
CRITICAL
Network
|
sap
|
commerce_cloud
|
SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation. This affects confidentiality and a…
|
CWE-611
XXE
|
CVE-2020-6238
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|