|
210621
|
7.5 |
HIGH
Network
|
python-rsa_project fedoraproject canonical
|
python-rsa fedora ubuntu_linux
|
Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application use…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-13757
|
2024-11-21 14:01 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210622
|
7.2 |
HIGH
Network
|
quickbox
|
quickbox
|
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as root without a password, which allows an attacker to obtain s…
|
CWE-306 CWE-269
Missing Authentication for Critical Function Improper Privilege Management
|
CVE-2020-13695
|
2024-11-21 14:01 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210623
|
8.8 |
HIGH
Network
|
quickbox
|
quickbox
|
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a password, which means that the www-data user can execute arbitrary …
|
CWE-78
OS Command
|
CVE-2020-13694
|
2024-11-21 14:01 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210624
|
8.8 |
HIGH
Network
|
quickbox
|
quickbox
|
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.
|
CWE-78
OS Command
|
CVE-2020-13448
|
2024-11-21 14:01 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210625
|
7.8 |
HIGH
Local
|
youhua
|
windows_master
|
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact b…
|
CWE-20
Improper Input Validation
|
CVE-2020-13634
|
2024-11-21 14:01 |
2020-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210626
|
9.8 |
CRITICAL
Network
|
bbpress
|
bbpress
|
An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.
|
NVD-CWE-noinfo
|
CVE-2020-13693
|
2024-11-21 14:01 |
2020-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210627
|
4.8 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13660
|
2024-11-21 14:01 |
2020-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210628
|
7.5 |
HIGH
Network
|
jerryscript
|
jerryscript
|
parser/js/js-scanner.c in JerryScript 2.2.0 mishandles errors during certain out-of-memory conditions, as demonstrated by a scanner_reverse_info_list NULL pointer dereference and a scanner_scan_all a…
|
CWE-754 CWE-476 CWE-617
Improper Check for Unusual or Exceptional Conditions NULL Pointer Dereference Reachable Assertion
|
CVE-2020-13649
|
2024-11-21 14:01 |
2020-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210629
|
3.2 |
LOW
Local
|
qemu debian opensuse canonical
|
qemu debian_linux leap ubuntu_linux
|
In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-13362
|
2024-11-21 14:01 |
2020-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210630
|
3.9 |
LOW
Local
|
qemu debian opensuse canonical
|
qemu debian_linux leap ubuntu_linux
|
In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count, which allows guest OS users to trigger an out-of-bounds access during an es1370_write…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13361
|
2024-11-21 14:01 |
2020-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|