|
210461
|
9.8 |
CRITICAL
Network
|
sophos
|
sfos
|
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with eithe…
|
CWE-89
SQL Injection
|
CVE-2020-12271
|
2024-11-21 13:59 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210462
|
9.8 |
CRITICAL
Network
|
artifex debian opensuse
|
jbig2dec debian_linux leap
|
jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12268
|
2024-11-21 13:59 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210463
|
9.8 |
CRITICAL
Network
|
qt
|
qt
|
setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.
|
CWE-416
Use After Free
|
CVE-2020-12267
|
2024-11-21 13:59 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210464
|
9.8 |
CRITICAL
Network
|
decompress_project
|
decompress
|
The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when a symlink is used, because of Directory Traversal.
|
CWE-22 CWE-59
Path Traversal Link Following
|
CVE-2020-12265
|
2024-11-21 13:59 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210465
|
7.8 |
HIGH
Local
|
avira
|
antivirus
|
Avira Antivirus before 5.0.2003.1821 on Windows allows privilege escalation or a denial of service via abuse of a symlink.
|
CWE-59
Link Following
|
CVE-2020-12254
|
2024-11-21 13:59 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210466
|
6.5 |
MEDIUM
Adjacent
|
bluezone
|
bluezone
|
React Native Bluetooth Scan in Bluezone 1.0.0 uses six-character alphanumeric IDs, which might make it easier for remote attackers to interfere with COVID-19 contact tracing by using many IDs. NOTE: …
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-12270
|
2024-11-21 13:59 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210467
|
7.5 |
HIGH
Network
|
advanced-woo-search
|
advanced_woo_search
|
The Advanced Woo Search plugin version through 1.99 for Wordpress suffers from a sensitive information disclosure vulnerability in every ajax search request via the sql field to includes/class-aws-se…
|
CWE-200
Information Exposure
|
CVE-2020-12070
|
2024-11-21 13:59 |
2020-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210468
|
6.1 |
MEDIUM
Network
|
grafana
|
grafana
|
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12245
|
2024-11-21 13:59 |
2020-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210469
|
6.1 |
MEDIUM
Network
|
gnu debian fedoraproject canonical opensuse
|
mailman debian_linux fedora ubuntu_linux leap backports_sle
|
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP repl…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12137
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210470
|
5.5 |
MEDIUM
Local
|
whoopsie_project mongodb
|
whoopsie c_driver
|
bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() parameter bytesNeeded could have an integer overflow …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-12135
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|