|
210841
|
5.4 |
MEDIUM
Network
|
boolebox
|
boolebox
|
BooleBox Secure File Sharing Utility before 4.2.3.0 allows stored XSS via a crafted avatar field within My Account JSON data to Account.aspx.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13248
|
2024-11-21 14:00 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210842
|
5.7 |
MEDIUM
Adjacent
|
sane-project canonical opensuse
|
sane_backends ubuntu_linux leap
|
A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-12866
|
2024-11-21 14:00 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210843
|
8.0 |
HIGH
Adjacent
|
sane-project debian canonical opensuse
|
sane_backends debian_linux ubuntu_linux leap
|
A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12865
|
2024-11-21 14:00 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210844
|
4.3 |
MEDIUM
Adjacent
|
sane-project opensuse canonical
|
sane_backends leap ubuntu_linux
|
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the prog…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-12864
|
2024-11-21 14:00 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210845
|
4.3 |
MEDIUM
Adjacent
|
sane-project debian canonical opensuse
|
sane_backends debian_linux ubuntu_linux leap
|
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the prog…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-12863
|
2024-11-21 14:00 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210846
|
4.3 |
MEDIUM
Adjacent
|
sane-project debian canonical opensuse
|
sane_backends debian_linux ubuntu_linux leap
|
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the prog…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-12862
|
2024-11-21 14:00 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210847
|
8.8 |
HIGH
Adjacent
|
sane-project canonical opensuse
|
sane_backends ubuntu_linux leap
|
A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12861
|
2024-11-21 14:00 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210848
|
6.5 |
MEDIUM
Network
|
nukeviet
|
nukeviet
|
modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=edit&userid= URI. The old password is not needed.
|
CWE-352
Origin Validation Error
|
CVE-2020-13157
|
2024-11-21 14:00 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210849
|
6.5 |
MEDIUM
Network
|
nukeviet
|
nukeviet
|
modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.
|
CWE-352
Origin Validation Error
|
CVE-2020-13156
|
2024-11-21 14:00 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210850
|
8.8 |
HIGH
Network
|
nukeviet
|
nukeviet
|
clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem URI.
|
CWE-352
Origin Validation Error
|
CVE-2020-13155
|
2024-11-21 14:00 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|