|
210861
|
5.5 |
MEDIUM
Local
|
jerryscript
|
jerryscript
|
An issue was discovered in ecma-helpers.c in jerryscript version 2.3.0, allows local attackers to cause a denial of service (DoS) (Null Pointer Dereference).
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-24187
|
2024-11-21 14:14 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210862
|
6.1 |
MEDIUM
Network
|
laborator
|
kalium
|
Cross Site Scripting (XSS) vulnerability in Name Input Field in Contact Us form in Laborator Kalium before 3.0.4, allows remote attackers to execute arbitrary code.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24075
|
2024-11-21 14:14 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210863
|
6.5 |
MEDIUM
Network
|
swoole
|
swoole
|
A HTTP response header injection vulnerability in Swoole v4.5.2 allows attackers to execute arbitrary code via supplying a crafted URL.
|
CWE-74
Injection
|
CVE-2020-24275
|
2024-11-21 14:14 |
2023-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210864
|
5.5 |
MEDIUM
Local
|
asn1c_project
|
asn1c
|
An issue was discovered in asn1c through v0.9.28. A NULL pointer dereference exists in the function _default_error_logger() located in asn1fix.c. It allows an attacker to cause Denial of Service.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-23911
|
2024-11-21 14:14 |
2023-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210865
|
5.5 |
MEDIUM
Local
|
asn1c_project
|
asn1c
|
Stack-based buffer overflow vulnerability in asn1c through v0.9.28 via function genhash_get in genhash.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-23910
|
2024-11-21 14:14 |
2023-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210866
|
7.1 |
HIGH
Local
|
advancemame
|
advancemame
|
Heap-based buffer over-read in function png_convert_4 in file pngex.cc in AdvanceMAME through 2.1.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-23909
|
2024-11-21 14:14 |
2023-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210867
|
9.8 |
CRITICAL
Network
|
victor_cms_project
|
victor_cms
|
SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request.
|
CWE-89
SQL Injection
|
CVE-2020-23966
|
2024-11-21 14:14 |
2023-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210868
|
7.8 |
HIGH
Local
|
mremoteng
|
mremoteng
|
An issue in mRemoteNG v1.76.20 allows attackers to escalate privileges via a crafted executable file. NOTE: third parties were unable to reproduce any scenario in which the claimed access of BUILTIN\…
|
CWE-269
Improper Privilege Management
|
CVE-2020-24307
|
2024-11-21 14:14 |
2023-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210869
|
6.1 |
MEDIUM
Network
|
github_readme_stats_project
|
github_readme_stats
|
Github Read Me Stats commit 3c7220e4f7144f6cb068fd433c774f6db47ccb95 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the function renderError.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23986
|
2024-11-21 14:14 |
2022-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210870
|
5.5 |
MEDIUM
Local
|
ffmpeg
|
ffmpeg
|
FFmpeg N-98388-g76a3ee996b allows attackers to cause a denial of service (DoS) via a crafted audio file due to insufficient verification of data authenticity.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-23906
|
2024-11-21 14:14 |
2021-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|