|
210541
|
6.1 |
MEDIUM
Network
|
digdash
|
digdash
|
An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200528, 2019R2 before p20200430, and 2020R1 before p20200507. A cross-site scripting (XSS) vulnerability exists in the log…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13652
|
2024-11-21 14:01 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210542
|
7.8 |
HIGH
Local
|
digdash
|
digdash
|
An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200421, and 2019R2 before p20200430. It allows a user to provide data that will be used to generate the JNLP file used by …
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2020-13651
|
2024-11-21 14:01 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210543
|
7.5 |
HIGH
Network
|
digdash
|
digdash
|
An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210. The login page is vulnerable to Server-Side Request Forgery (SSRF) that allows use of the application as a prox…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-13650
|
2024-11-21 14:01 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210544
|
9.8 |
CRITICAL
Network
|
morganstanley
|
hobbes
|
In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remo…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-13656
|
2024-11-21 14:01 |
2020-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210545
|
10.0 |
CRITICAL
Network
|
the_rolling_proximity_identifier_project
|
the_rolling_proximity_identifier
|
The Rolling Proximity Identifier used in the Apple/Google Exposure Notification API beta through 2020-05-29 enables attackers to circumvent Bluetooth Smart Privacy because there is a secondary tempor…
|
CWE-200
Information Exposure
|
CVE-2020-13702
|
2024-11-21 14:01 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210546
|
8.8 |
HIGH
Network
|
liferay
|
liferay_portal
|
In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not restrict user access to sensitive objects, which al…
|
CWE-74 CWE-862
Injection Missing Authorization
|
CVE-2020-13445
|
2024-11-21 14:01 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210547
|
6.5 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which…
|
NVD-CWE-noinfo
|
CVE-2020-13444
|
2024-11-21 14:01 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210548
|
5.5 |
MEDIUM
Local
|
arm opensuse
|
cortex-a32_firmware cortex-a35_firmware cortex-a53_firmware cortex-a57_firmware cortex-a72_firmware cortex-a73_firmware cortex-a34_firmware leap
|
Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via …
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-13844
|
2024-11-21 14:01 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210549
|
7.8 |
HIGH
Local
|
videolan debian
|
vlc_media_player debian_linux
|
A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13428
|
2024-11-21 14:01 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210550
|
7.5 |
HIGH
Network
|
rejetto
|
http_file_server
|
rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access violation via concurrent HTTP requests …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-13432
|
2024-11-21 14:01 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|