|
209771
|
5.5 |
MEDIUM
Local
|
whoopsie_project
|
whoopsie
|
The parse_report() function in whoopsie.c in Whoopsie through 0.2.69 mishandles memory allocation failures, which allows an attacker to cause a denial of service via a malformed crash file.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-15570
|
2024-11-21 14:05 |
2020-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209772
|
5.5 |
MEDIUM
Local
|
milkytracker_project debian
|
milkytracker debian_linux
|
PlayerGeneric.cpp in MilkyTracker through 1.02.00 has a use-after-free in the PlayerGeneric destructor.
|
CWE-416
Use After Free
|
CVE-2020-15569
|
2024-11-21 14:05 |
2020-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209773
|
6.1 |
MEDIUM
Network
|
roundcube debian
|
webmail debian_linux
|
An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in th…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15562
|
2024-11-21 14:05 |
2020-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209774
|
9.8 |
CRITICAL
Network
|
solarwinds
|
serv-u_ftp_server
|
SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.
|
CWE-20
Improper Input Validation
|
CVE-2020-15543
|
2024-11-21 14:05 |
2020-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209775
|
9.8 |
CRITICAL
Network
|
solarwinds
|
serv-u_ftp_server
|
SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.
|
NVD-CWE-noinfo
|
CVE-2020-15542
|
2024-11-21 14:05 |
2020-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209776
|
9.8 |
CRITICAL
Network
|
solarwinds
|
serv-u_ftp_server
|
SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.
|
NVD-CWE-noinfo
|
CVE-2020-15541
|
2024-11-21 14:05 |
2020-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209777
|
9.8 |
CRITICAL
Network
|
we-com
|
opendata_cms
|
We-com OpenData CMS 2.0 allows SQL Injection via the username field on the administrator login page.
|
CWE-89
SQL Injection
|
CVE-2020-15540
|
2024-11-21 14:05 |
2020-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209778
|
9.8 |
CRITICAL
Network
|
we-com
|
municipality_portal_cms
|
SQL injection can occur in We-com Municipality portal CMS 2.1.x via the cerca/ keywords field.
|
CWE-89
SQL Injection
|
CVE-2020-15539
|
2024-11-21 14:05 |
2020-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209779
|
6.1 |
MEDIUM
Network
|
we-com
|
municipality_portal_cms
|
XSS can occur in We-com Municipality portal CMS 2.1.x via the cerca/ search bar.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15538
|
2024-11-21 14:05 |
2020-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209780
|
6.1 |
MEDIUM
Network
|
vanguard_project
|
vanguard
|
An issue was discovered in the Vanguard plugin 2.1 for WordPress. XSS can occur via the mails/new title field, a product field to the p/ URI, or the Products Search box.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15537
|
2024-11-21 14:05 |
2020-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|