|
209801
|
9.1 |
CRITICAL
Network
|
ntop
|
ndpi
|
In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-15471
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209802
|
5.5 |
MEDIUM
Local
|
rockcarry
|
ffjpeg
|
ffjpeg through 2020-02-24 has a heap-based buffer overflow in jfif_decode in jfif.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-15470
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209803
|
9.8 |
CRITICAL
Network
|
persian_vip_download_script_project
|
persian_vip_download_script
|
Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter.
|
CWE-89
SQL Injection
|
CVE-2020-15468
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209804
|
6.1 |
MEDIUM
Network
|
nozominetworks
|
guardian
|
Nozomi Guardian before 19.0.4 allows attackers to achieve stored XSS (in the web front end) by leveraging the ability to create a custom field with a crafted field name.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15307
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209805
|
9.8 |
CRITICAL
Network
|
draytek
|
vigor3900_firmware vigor2960_firmware vigor300b_firmware
|
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-pytho…
|
CWE-78
OS Command
|
CVE-2020-15415
|
2024-11-21 14:05 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209806
|
4.3 |
MEDIUM
Network
|
misp
|
misp
|
An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding to allow a user to send an event contact form.
|
CWE-862
Missing Authorization
|
CVE-2020-15412
|
2024-11-21 14:05 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209807
|
9.8 |
CRITICAL
Network
|
misp
|
misp
|
An issue was discovered in MISP 2.4.128. app/Controller/AttributesController.php has insufficient ACL checks in the attachment downloader.
|
NVD-CWE-noinfo
|
CVE-2020-15411
|
2024-11-21 14:05 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209808
|
4.4 |
MEDIUM
Local
|
iobit
|
malware_fighter
|
IOBit Malware Fighter Pro 8.0.2.547 allows local users to gain privileges for file deletion by manipulating malicious flagged file locations with an NTFS junction and an Object Manager symbolic link.
|
CWE-59
Link Following
|
CVE-2020-15401
|
2024-11-21 14:05 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209809
|
4.3 |
MEDIUM
Network
|
cakefoundation
|
cakephp
|
CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2020-15400
|
2024-11-21 14:05 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209810
|
7.8 |
HIGH
Local
|
hylafax\+_project ifax
|
hylafax\+ hylafax_enterprise
|
HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileged users (e.g., locations under /var/spool/hylafax that are writable by the uuc…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-15397
|
2024-11-21 14:05 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|