|
209791
|
7.5 |
HIGH
Network
|
duckduckgo
|
duckduckgo
|
The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests to servers in the duckduckgo.com domain, which mig…
|
CWE-200
Information Exposure
|
CVE-2020-15502
|
2024-11-21 14:05 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209792
|
6.1 |
MEDIUM
Network
|
tileserver
|
tileservergl
|
An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflect…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15500
|
2024-11-21 14:05 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209793
|
9.8 |
CRITICAL
Network
|
wavlink
|
wl-wn530hg4_firmware
|
An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple buffer overflow vulnerabilities exist in CGI scripts, leading to remote code execution with root privileges. (The …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-15490
|
2024-11-21 14:05 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209794
|
9.8 |
CRITICAL
Network
|
wavlink
|
wl-wn530hg4_firmware
|
An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulnerabilities exist in CGI scripts, leading to remote code execution with root pri…
|
CWE-78
OS Command
|
CVE-2020-15489
|
2024-11-21 14:05 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209795
|
7.5 |
HIGH
Network
|
journal-theme
|
journal
|
The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-15478
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209796
|
7.5 |
HIGH
Network
|
ntop debian
|
ndpi debian_linux
|
In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-15476
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209797
|
9.8 |
CRITICAL
Network
|
ntop
|
ndpi
|
In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.
|
CWE-416
Use After Free
|
CVE-2020-15475
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209798
|
9.8 |
CRITICAL
Network
|
ntop
|
ndpi
|
In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-15474
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209799
|
9.1 |
CRITICAL
Network
|
ntop
|
ndpi
|
In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-15473
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209800
|
9.1 |
CRITICAL
Network
|
ntop debian
|
ndpi debian_linux
|
In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-15472
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|