|
211661
|
5.5 |
MEDIUM
Local
|
zim-wiki
|
zim
|
Zim through 0.72.1 creates temporary directories with predictable names. A malicious user could predict and create Zim's temporary directories and prevent other users from being able to start Zim, re…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-10870
|
2024-11-21 13:56 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211662
|
8.8 |
HIGH
Network
|
codeigniter
|
codeigniter
|
CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the User" page. NOTE: A contributor to the CodeIgniter framework argues that the is…
|
CWE-269
Improper Privilege Management
|
CVE-2020-10793
|
2024-11-21 13:56 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211663
|
4.8 |
MEDIUM
Network
|
nagios
|
nagios_xi
|
Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10821
|
2024-11-21 13:56 |
2020-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211664
|
4.8 |
MEDIUM
Network
|
nagios
|
nagios_xi
|
Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ password parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10820
|
2024-11-21 13:56 |
2020-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211665
|
4.8 |
MEDIUM
Network
|
nagios
|
nagios_xi
|
Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10819
|
2024-11-21 13:56 |
2020-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211666
|
7.2 |
HIGH
Network
|
articatech
|
artica_proxy
|
Artica Proxy 4.26 allows remote command execution for an authenticated user via shell metacharacters in the "Modify the hostname" field.
|
CWE-78
OS Command
|
CVE-2020-10818
|
2024-11-21 13:56 |
2020-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211667
|
5.5 |
MEDIUM
Local
|
hdfgroup
|
hdf5
|
An issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5F_get_nrefs() located in H5Fquery.c. It allows an attacker to cause Denial of Service.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-10812
|
2024-11-21 13:56 |
2020-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211668
|
5.5 |
MEDIUM
Local
|
hdfgroup
|
hdf5
|
An issue was discovered in HDF5 through 1.12.0. A heap-based buffer over-read exists in the function H5O__layout_decode() located in H5Olayout.c. It allows an attacker to cause Denial of Service.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-10811
|
2024-11-21 13:56 |
2020-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211669
|
5.5 |
MEDIUM
Local
|
hdfgroup
|
hdf5
|
An issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5AC_unpin_entry() located in H5AC.c. It allows an attacker to cause Denial of Service.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-10810
|
2024-11-21 13:56 |
2020-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211670
|
5.5 |
MEDIUM
Local
|
hdfgroup
|
hdf5
|
An issue was discovered in HDF5 through 1.12.0. A heap-based buffer overflow exists in the function Decompress() located in decompress.c. It can be triggered by sending a crafted file to the gif2h5 b…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10809
|
2024-11-21 13:56 |
2020-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|