|
211401
|
9.8 |
CRITICAL
Network
|
chocolate-doom opensuse
|
crispy_doom chocolate_doom leap backports
|
The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading to a buffer overflow. A malicious user can overwrite the server's stack.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-14983
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211402
|
5.9 |
MEDIUM
Network
|
vipre
|
password_vault
|
The ThreatTrack VIPRE Password Vault app through 1.100.1090 for iOS has Missing SSL Certificate Validation.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-14981
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211403
|
5.9 |
MEDIUM
Network
|
sophos
|
sophos_secure_email
|
The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-14980
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211404
|
6.1 |
MEDIUM
Network
|
webtareas_project
|
webtareas
|
The loginForm within the general/login.php webpage in webTareas 2.0p8 suffers from a Reflected Cross Site Scripting (XSS) vulnerability via the query string.
|
CWE-79
Cross-site Scripting
|
CVE-2020-14973
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211405
|
9.8 |
CRITICAL
Network
|
pisay_online_e-learning_system_project
|
pisay_online_e-learning_system
|
Multiple SQL injection vulnerabilities in Sourcecodester Pisay Online E-Learning System 1.0 allow remote unauthenticated attackers to bypass authentication and achieve Remote Code Execution (RCE) via…
|
CWE-89
SQL Injection
|
CVE-2020-14972
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211406
|
7.5 |
HIGH
Network
|
misp
|
misp
|
app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable a…
|
CWE-862
Missing Authorization
|
CVE-2020-14969
|
2024-11-21 14:04 |
2020-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211407
|
9.8 |
CRITICAL
Network
|
jsrsasign_project netapp
|
jsrsasign max_data
|
An issue was discovered in the jsrsasign package before 8.0.17 for Node.js. Its RSASSA-PSS (RSA-PSS) implementation does not detect signature manipulation/modification by prepending '\0' bytes to a s…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-14968
|
2024-11-21 14:04 |
2020-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211408
|
9.8 |
CRITICAL
Network
|
jsrsasign_project netapp
|
jsrsasign max_data
|
An issue was discovered in the jsrsasign package before 8.0.18 for Node.js. Its RSA PKCS1 v1.5 decryption implementation does not detect ciphertext modification by prepending '\0' bytes to ciphertext…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-14967
|
2024-11-21 14:04 |
2020-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211409
|
7.5 |
HIGH
Network
|
jsrsasign_project netapp
|
jsrsasign max_data
|
An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signatures by not checking overflows in the length of a sequence and '0' characters appe…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-14966
|
2024-11-21 14:04 |
2020-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211410
|
5.4 |
MEDIUM
Network
|
machothemes
|
image_photo_gallery_final_tiles_grid
|
Multiple XSS vulnerabilities in the Final Tiles Gallery plugin before 3.4.19 for WordPress allow remote attackers to inject arbitrary web script or HTML via the Title (aka imageTitle) or Caption (aka…
|
CWE-79
Cross-site Scripting
|
CVE-2020-14962
|
2024-11-21 14:04 |
2020-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|