|
210411
|
7.8 |
HIGH
Local
|
pixar
|
openusd
|
A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. A specially crafted USDC file format path jumps decompression heap overfl…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13493
|
2024-11-21 14:01 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210412
|
8.8 |
HIGH
Network
|
fastweb
|
fastgate_gpon_fga2130fwb_firmware
|
Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's ability to perform administrative actions such as modifying th…
|
CWE-352
Origin Validation Error
|
CVE-2020-13620
|
2024-11-21 14:01 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210413
|
8.8 |
HIGH
Network
|
drupal fedoraproject
|
drupal fedora
|
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP f…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-13671
|
2024-11-21 14:01 |
2020-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210414
|
7.6 |
HIGH
Network
|
gitlab
|
gitlab
|
The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and ot…
|
NVD-CWE-noinfo
|
CVE-2020-13359
|
2024-11-21 14:01 |
2020-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210415
|
8.2 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protection and read files in certain specific paths on the …
|
NVD-CWE-noinfo
|
CVE-2020-13356
|
2024-11-21 14:01 |
2020-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210416
|
8.1 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwrite certain specific paths on the server.…
|
CWE-22
Path Traversal
|
CVE-2020-13355
|
2024-11-21 14:01 |
2020-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210417
|
6.8 |
MEDIUM
Physics
|
westerndigital linaro
|
inand_cl_em132_firmware inand_ix_em132_firmware inand_ix_em132_xi_firmware op-tee
|
Western Digital has identified a security vulnerability in the Replay Protected Memory Block (RPMB) protocol as specified in multiple standards for storage device interfaces, including all versions o…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2020-13799
|
2024-11-21 14:01 |
2020-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210418
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a file path resulted in the Advanced Search feature susceptible to catastrophic ba…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-13349
|
2024-11-21 14:01 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210419
|
5.7 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected version…
|
NVD-CWE-noinfo
|
CVE-2020-13348
|
2024-11-21 14:01 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210420
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affect…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13351
|
2024-11-21 14:01 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|