|
211561
|
7.8 |
HIGH
Local
|
softmaker
|
office_textmaker_2021
|
In SoftMaker Software GmbH SoftMaker Office TextMaker 2021 (revision 1014), a specially crafted document can cause the document parser to miscalculate a length used to allocate a buffer, later upon u…
|
CWE-787 CWE-131
Out-of-bounds Write Incorrect Calculation of Buffer Size
|
CVE-2020-13546
|
2024-11-21 14:01 |
2021-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211562
|
5.7 |
MEDIUM
Adjacent
|
tufin
|
securetrack
|
Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in version R20-2 GA.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-13462
|
2024-11-21 14:01 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211563
|
4.3 |
MEDIUM
Adjacent
|
tufin
|
securetrack
|
Username enumeration in present in Tufin SecureTrack. It's affecting all versions of SecureTrack. The vendor has decided not to fix this vulnerability. Vendor's response: "This attack requires access…
|
NVD-CWE-noinfo
|
CVE-2020-13461
|
2024-11-21 14:01 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211564
|
8.8 |
HIGH
Network
|
tufin
|
securetrack
|
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to R20-2 GA.
|
CWE-352
Origin Validation Error
|
CVE-2020-13460
|
2024-11-21 14:01 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211565
|
5.9 |
MEDIUM
Adjacent
|
tufin
|
securetrack
|
Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or …
|
CWE-79
Cross-site Scripting
|
CVE-2020-13409
|
2024-11-21 14:01 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211566
|
5.9 |
MEDIUM
Adjacent
|
tufin
|
securetrack
|
Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or …
|
CWE-79
Cross-site Scripting
|
CVE-2020-13408
|
2024-11-21 14:01 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211567
|
5.9 |
MEDIUM
Adjacent
|
tufin
|
securetrack
|
Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or …
|
CWE-79
Cross-site Scripting
|
CVE-2020-13407
|
2024-11-21 14:01 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211568
|
7.8 |
HIGH
Local
|
softmaker
|
planmaker_2021
|
A memory corruption vulnerability exists in the Excel Document SST Record 0x00fc functionality of SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014). A specially crafted malforme…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13586
|
2024-11-21 14:01 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211569
|
7.8 |
HIGH
Local
|
softmaker
|
planmaker_2021
|
An exploitable heap-based buffer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker application. A specially crafted document can cause…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13580
|
2024-11-21 14:01 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211570
|
7.8 |
HIGH
Local
|
softmaker
|
planmaker_2021
|
An exploitable integer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker application. A specially crafted document can cause the docum…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2020-13579
|
2024-11-21 14:01 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|