|
197581
|
9.8 |
CRITICAL
Network
|
nethack
|
nethack
|
In NetHack before 3.6.5, detecting an unknown configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects syst…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-5214
|
2024-11-21 14:33 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197582
|
9.8 |
CRITICAL
Network
|
nethack
|
nethack
|
In NetHack before 3.6.5, too long of a value for the SYMBOL configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerabilit…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-5213
|
2024-11-21 14:33 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197583
|
9.8 |
CRITICAL
Network
|
nethack
|
nethack
|
In NetHack before 3.6.5, an extremely long value for the MENUCOLOR configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulne…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-5212
|
2024-11-21 14:33 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197584
|
7.8 |
HIGH
Local
|
nethack
|
nethack
|
In NetHack before 3.6.5, an invalid argument to the -w command line option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects s…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-5210
|
2024-11-21 14:33 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197585
|
7.8 |
HIGH
Local
|
nethack
|
nethack
|
In NetHack before 3.6.5, unknown options starting with -de and -i can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems th…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-5209
|
2024-11-21 14:33 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197586
|
7.5 |
HIGH
Network
|
jetbrains
|
ktor
|
In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-5207
|
2024-11-21 14:33 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197587
|
5.3 |
MEDIUM
Network
|
sylius
|
syliusresourcebundle
|
Sylius ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. This might lead to data exposure by using an unintended serialisation group - for example it could make…
|
CWE-200
Information Exposure
|
CVE-2020-5220
|
2024-11-21 14:33 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197588
|
4.3 |
MEDIUM
Network
|
sylius
|
sylius
|
Affected versions of Sylius give attackers the ability to switch channels via the _channel_code GET parameter in production environments. This was meant to be enabled only when kernel.debug is set to…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-5218
|
2024-11-21 14:33 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197589
|
5.4 |
MEDIUM
Network
|
simplesamlphp
|
simplesamlphp
|
Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script allows error reports to be submitted and sent to the system administrator. Starting with SimpleSAMLphp 1.18.…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5226
|
2024-11-21 14:33 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197590
|
5.4 |
MEDIUM
Network
|
simplesamlphp
|
simplesamlphp
|
Log injection in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script, which receives error reports and sends them via email to the system administrator, did not properly sanitize the r…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-5225
|
2024-11-21 14:33 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|