|
210331
|
8.8 |
HIGH
Network
|
veeam
|
veeam_availability_suite veeam_backup_\&_replication
|
VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over filesystem I/O req…
|
CWE-862
Missing Authorization
|
CVE-2020-15518
|
2024-11-21 14:05 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210332
|
2.3 |
LOW
Local
|
qemu debian
|
qemu debian_linux
|
In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-15469
|
2024-11-21 14:05 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210333
|
7.5 |
HIGH
Network
|
libraw fedoraproject debian
|
libraw fedora debian_linux
|
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed…
|
CWE-20
Improper Input Validation
|
CVE-2020-15503
|
2024-11-21 14:05 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210334
|
7.5 |
HIGH
Network
|
duckduckgo
|
duckduckgo
|
The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests to servers in the duckduckgo.com domain, which mig…
|
CWE-200
Information Exposure
|
CVE-2020-15502
|
2024-11-21 14:05 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210335
|
6.1 |
MEDIUM
Network
|
tileserver
|
tileservergl
|
An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflect…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15500
|
2024-11-21 14:05 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210336
|
9.8 |
CRITICAL
Network
|
wavlink
|
wl-wn530hg4_firmware
|
An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple buffer overflow vulnerabilities exist in CGI scripts, leading to remote code execution with root privileges. (The …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-15490
|
2024-11-21 14:05 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210337
|
9.8 |
CRITICAL
Network
|
wavlink
|
wl-wn530hg4_firmware
|
An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulnerabilities exist in CGI scripts, leading to remote code execution with root pri…
|
CWE-78
OS Command
|
CVE-2020-15489
|
2024-11-21 14:05 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210338
|
7.5 |
HIGH
Network
|
journal-theme
|
journal
|
The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-15478
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210339
|
7.5 |
HIGH
Network
|
ntop debian
|
ndpi debian_linux
|
In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-15476
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210340
|
9.8 |
CRITICAL
Network
|
ntop
|
ndpi
|
In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.
|
CWE-416
Use After Free
|
CVE-2020-15475
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|