|
208601
|
8.8 |
HIGH
Network
|
totolink
|
a3002r_firmware a3002ru-v1_firmware a3002ru-v2_firmware a702r-v2_firmware a702r-v3_firmware n100re-v3_firmware n150rt_firmware n200re-v3_firmware n200re-v4_firmware n210re_…
|
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.
|
CWE-78 CWE-862
OS Command Missing Authorization
|
CVE-2020-25499
|
2024-11-21 14:18 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208602
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.
|
-
|
CVE-2020-25627
|
2024-11-21 14:18 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208603
|
5.5 |
MEDIUM
Local
|
imagemagick debian
|
imagemagick debian_linux
|
In CatromWeights(), MeshInterpolate(), InterpolatePixelChannel(), InterpolatePixelChannels(), and InterpolatePixelInfo(), which are all functions in /MagickCore/pixel.c, there were multiple unconstra…
|
-
|
CVE-2020-25676
|
2024-11-21 14:18 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208604
|
3.3 |
LOW
Local
|
imagemagick debian
|
imagemagick debian_linux
|
In the CropImage() and CropImageToTiles() routines of MagickCore/transform.c, rounding calculations performed on unconstrained pixel offsets was causing undefined behavior in the form of integer over…
|
-
|
CVE-2020-25675
|
2024-11-21 14:18 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208605
|
5.5 |
MEDIUM
Local
|
imagemagick debian
|
imagemagick debian_linux
|
WriteOnePNGImage() from coders/png.c (the PNG coder) has a for loop with an improper exit condition that can allow an out-of-bounds READ via heap-buffer-overflow. This occurs because it is possible f…
|
-
|
CVE-2020-25674
|
2024-11-21 14:18 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208606
|
5.5 |
MEDIUM
Local
|
imagemagick
|
imagemagick
|
TIFFGetProfiles() in /coders/tiff.c calls strstr() which causes a large out-of-bounds read when it searches for `"dc:format=\"image/dng\"` within `profile` due to improper string handling, when a cra…
|
-
|
CVE-2020-25667
|
2024-11-21 14:18 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208607
|
3.3 |
LOW
Local
|
imagemagick debian
|
imagemagick debian_linux
|
There are 4 places in HistogramCompare() in MagickCore/histogram.c where an integer overflow is possible during simple math calculations. This occurs in the rgb values and `count` value for a color. …
|
-
|
CVE-2020-25666
|
2024-11-21 14:18 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208608
|
5.5 |
MEDIUM
Local
|
imagemagick debian
|
imagemagick debian_linux
|
The PALM image coder at coders/palm.c makes an improper call to AcquireQuantumMemory() in routine WritePALMImage() because it needs to be offset by 256. This can cause a out-of-bounds read later on i…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-25665
|
2024-11-21 14:18 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208609
|
6.1 |
MEDIUM
Local
|
imagemagick fedoraproject
|
imagemagick fedora
|
In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-pr…
|
-
|
CVE-2020-25664
|
2024-11-21 14:18 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208610
|
5.5 |
MEDIUM
Local
|
imagemagick
|
imagemagick
|
A call to ConformPixelInfo() in the SetImageAlphaChannel() routine of /MagickCore/channel.c caused a subsequent heap-use-after-free or heap-buffer-overflow READ when GetPixelRed() or GetPixelBlue() w…
|
-
|
CVE-2020-25663
|
2024-11-21 14:18 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|