|
210691
|
5.5 |
MEDIUM
Local
|
whoopsie_project mongodb
|
whoopsie c_driver
|
bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() parameter bytesNeeded could have an integer overflow …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-12135
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210692
|
9.8 |
CRITICAL
Network
|
nanometrics
|
titansma centaur
|
Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2020-12134
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210693
|
6.1 |
MEDIUM
Network
|
fifthplay
|
s.a.m.i
|
Fifthplay S.A.M.I before 2019.3_HP2 allows unauthenticated stored XSS via a POST request.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12132
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210694
|
6.1 |
MEDIUM
Network
|
app2pro
|
airdisk_pro
|
The AirDisk Pro app 5.5.3 for iOS allows XSS via the devicename parameter (shown next to the UI logo).
|
CWE-79
Cross-site Scripting
|
CVE-2020-12131
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210695
|
5.3 |
MEDIUM
Network
|
postfix
|
postfix
|
A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demonstrated by the similarity of \xce\xbf to the 'o' character…
|
NVD-CWE-Other
|
CVE-2020-12063
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210696
|
6.1 |
MEDIUM
Network
|
app2pro
|
airdisk_pro
|
The AirDisk Pro app 5.5.3 for iOS allows XSS via the deleteFile parameter of the Delete function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12130
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210697
|
6.1 |
MEDIUM
Network
|
app2pro
|
airdisk_pro
|
The AirDisk Pro app 5.5.3 for iOS allows XSS via the createFolder parameter of the Create Folder function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12129
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210698
|
7.5 |
HIGH
Network
|
file_transfer_ifamily_project
|
file_transfer_ifamily
|
DONG JOO CHO File Transfer iFamily 2.1 allows directory traversal related to the ./etc/ path.
|
CWE-22
Path Traversal
|
CVE-2020-12128
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210699
|
8.2 |
HIGH
Network
|
binance
|
tss-lib
|
The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensitive information fro…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-12118
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210700
|
6.1 |
MEDIUM
Network
|
bigbluebutton
|
bigbluebutton
|
BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12113
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|