|
210571
|
7.5 |
HIGH
Network
|
foxitsoftware
|
reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It allows stack consumption via a loop of an indirect object reference.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-13815
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210572
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It has a use-after-free via a document that lacks a dictionary.
|
CWE-416
Use After Free
|
CVE-2020-13814
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210573
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_studio_photo
|
An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted DLL in the current working directory when FoxitStudioPhoto366_3.6.6.916.exe is u…
|
CWE-426
Untrusted Search Path
|
CVE-2020-13813
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210574
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_studio_photo
|
An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted DLL in the current working directory.
|
CWE-426
Untrusted Search Path
|
CVE-2020-13812
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210575
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_studio_photo
|
An issue was discovered in Foxit Studio Photo before 3.6.6.922. It has an out-of-bounds write via a crafted TIFF file.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13811
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210576
|
6.0 |
MEDIUM
Local
|
qemu canonical opensuse
|
qemu ubuntu_linux leap
|
ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mm_index value during an ati_mm_read or ati_mm_write call.
|
CWE-674
Uncontrolled Recursion
|
CVE-2020-13800
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210577
|
5.5 |
MEDIUM
Local
|
qemu
|
qemu
|
hw/pci/pci.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access by providing an address near the end of the PCI configuration space.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-13791
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210578
|
5.6 |
MEDIUM
Network
|
qemu canonical debian
|
qemu ubuntu_linux debian_linux
|
rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid memory copy operation.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13765
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210579
|
7.7 |
HIGH
Network
|
postgresql quarkus netapp fedoraproject debian
|
postgresql_jdbc_driver quarkus steelstore_cloud_integrated_storage fedora debian_linux
|
PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.
|
CWE-611
XXE
|
CVE-2020-13692
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210580
|
6.1 |
MEDIUM
Network
|
phplist
|
phplist
|
phpList before 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13827
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|