|
210911
|
5.5 |
MEDIUM
Local
|
sane-project fedoraproject debian opensuse canonical
|
sane_backends fedora debian_linux leap ubuntu_linux
|
A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-20…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-12867
|
2024-11-21 14:00 |
2020-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210912
|
8.8 |
HIGH
Network
|
mappresspro
|
mappress
|
The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related to creation/retrieval/deletion of PHP template file…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12675
|
2024-11-21 14:00 |
2020-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210913
|
7.8 |
HIGH
Local
|
teradici
|
pcoip_graphics_agent pcoip_standard_agent
|
Initialization of the pcoip_credential_provider in Teradici PCoIP Standard Agent for Windows and PCoIP Graphics Agent for Windows versions 19.11.1 and earlier creates an insecure named pipe, which al…
|
CWE-362
Race Condition
|
CVE-2020-13173
|
2024-11-21 14:00 |
2020-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210914
|
5.9 |
MEDIUM
Network
|
netgear
|
r6120_firmware r6220_firmware r6350_firmware r6400_firmware r6800_firmware r6850_firmware r7000p_firmware r7800_firmware r8000_firmware r9000_firmware rax120_firmware
|
Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibly R6120, R7800, R6220, R8000, R6350, R9000, R6400,…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-13245
|
2024-11-21 14:00 |
2020-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210915
|
5.5 |
MEDIUM
Local
|
qemu canonical debian
|
qemu ubuntu_linux debian_linux
|
sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS user can crash the QEMU process.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-13253
|
2024-11-21 14:00 |
2020-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210916
|
8.1 |
HIGH
Network
|
schedmd fedoraproject opensuse debian
|
slurm fedora leap debian_linux
|
Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A race condition allows …
|
NVD-CWE-Other
|
CVE-2020-12693
|
2024-11-21 14:00 |
2020-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210917
|
6.1 |
MEDIUM
Network
|
contentful
|
python_example
|
Contentful through 2020-05-21 for Python allows reflected XSS, as demonstrated by the api parameter to the-example-app.py.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13258
|
2024-11-21 14:00 |
2020-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210918
|
8.2 |
HIGH
Network
|
libexif_project debian canonical opensuse
|
libexif debian_linux ubuntu_linux leap
|
An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2020-13113
|
2024-11-21 14:00 |
2020-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210919
|
9.8 |
CRITICAL
Network
|
pango
|
virtual_private_network_software_development_kit
|
An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations over a socket bound to localhost. Binding to the socket and providing a path whe…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12828
|
2024-11-21 14:00 |
2020-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210920
|
7.5 |
HIGH
Network
|
libexif_project canonical opensuse
|
libexif ubuntu_linux leap
|
An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-13114
|
2024-11-21 14:00 |
2020-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|