|
196231
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-7967
|
2024-11-21 14:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196232
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2020-7966
|
2024-11-21 14:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196233
|
9.8 |
CRITICAL
Network
|
gitlab
|
gitlab
|
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-8114
|
2024-11-21 14:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196234
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-7979
|
2024-11-21 14:38 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196235
|
7.5 |
HIGH
Network
|
squid-cache opensuse canonical
|
squid leap ubuntu_linux
|
An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may write to memory outside the credentials buffer. On …
|
CWE-20 CWE-787
Improper Input Validation Out-of-bounds Write
|
CVE-2020-8517
|
2024-11-21 14:38 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196236
|
7.3 |
HIGH
Network
|
squid-cache canonical opensuse fedoraproject debian
|
squid ubuntu_linux leap fedora debian_linux
|
An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.
|
CWE-787 CWE-131
Out-of-bounds Write Incorrect Calculation of Buffer Size
|
CVE-2020-8450
|
2024-11-21 14:38 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196237
|
7.5 |
HIGH
Network
|
squid-cache debian canonical opensuse fedoraproject
|
squid debian_linux ubuntu_linux leap fedora
|
An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security fi…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-8449
|
2024-11-21 14:38 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196238
|
9.8 |
CRITICAL
Network
|
klona_project
|
klona
|
Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using klona.
|
CWE-20
Improper Input Validation
|
CVE-2020-8125
|
2024-11-21 14:38 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196239
|
5.3 |
MEDIUM
Network
|
url-parse_project
|
url-parse
|
Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.
|
CWE-20
Improper Input Validation
|
CVE-2020-8124
|
2024-11-21 14:38 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196240
|
4.9 |
MEDIUM
Network
|
strapi
|
strapi
|
A denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin rights can lead to arbitrary restart of the application.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-8123
|
2024-11-21 14:38 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|