|
198261
|
3.3 |
LOW
Local
|
gnu netapp
|
binutils ontap_select_deploy_administration_utility
|
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c beca…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-35448
|
2024-11-21 14:27 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198262
|
8.1 |
HIGH
Network
|
fasterxml debian netapp oracle
|
jackson-databind debian_linux service_level_manager webcenter_portal application_testing_suite primavera_unifier agile_plm communications_policy_management communications_bill…
|
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka e…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-35728
|
2024-11-21 14:27 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198263
|
6.1 |
MEDIUM
Network
|
crossbar
|
autobahn
|
Autobahn|Python before 20.12.3 allows redirect header injection.
|
CWE-601
Open Redirect
|
CVE-2020-35678
|
2024-11-21 14:27 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198264
|
9.8 |
CRITICAL
Network
|
flamingo_project
|
flamingo
|
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addUser.
|
CWE-89
SQL Injection
|
CVE-2020-35245
|
2024-11-21 14:27 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198265
|
9.8 |
CRITICAL
Network
|
flamingo_project
|
flamingo
|
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addGroup.
|
CWE-89
SQL Injection
|
CVE-2020-35244
|
2024-11-21 14:27 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198266
|
9.8 |
CRITICAL
Network
|
flamingo_project
|
flamingo
|
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserInfoInDb.
|
CWE-89
SQL Injection
|
CVE-2020-35243
|
2024-11-21 14:27 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198267
|
9.8 |
CRITICAL
Network
|
flamingo_project
|
flamingo
|
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserTeamInfoInDbAndMemory.
|
CWE-89
SQL Injection
|
CVE-2020-35242
|
2024-11-21 14:27 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198268
|
9.8 |
CRITICAL
Network
|
huorong
|
internet_security
|
Beijing Huorong Internet Security 5.0.55.2 allows a non-admin user to escalate privileges by injecting code into a process, and then waiting for a Huorong services restart or a system reboot.
|
NVD-CWE-noinfo
|
CVE-2020-35364
|
2024-11-21 14:27 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198269
|
7.5 |
HIGH
Network
|
dext5
|
dext5upload
|
DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow remote files to be downloaded via a dext5CMD=downloadRequest action with traversal…
|
CWE-22
Path Traversal
|
CVE-2020-35362
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198270
|
7.5 |
HIGH
Network
|
flamingoim_project
|
flamingoim
|
Flamingo (aka FlamingoIM) through 2020-09-29 allows ../ directory traversal because the only ostensibly unpredictable part of a file-transfer request is an MD5 computation; however, this computation …
|
CWE-22
Path Traversal
|
CVE-2020-35284
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|