|
208271
|
5.5 |
MEDIUM
Local
|
linux debian
|
linux_kernel debian_linux
|
A vulnerability was found in Linux Kernel where in the spk_ttyio_receive_buf2() function, it would dereference spk_ttyio_synth without checking whether it is NULL or not, and may lead to a NULL-ptr d…
|
-
|
CVE-2020-27830
|
2024-11-21 14:21 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208272
|
7.8 |
HIGH
Local
|
uclouvain fedoraproject debian
|
openjpeg fedora debian_linux
|
A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to co…
|
CWE-787 CWE-120
Out-of-bounds Write Classic Buffer Overflow
|
CVE-2020-27823
|
2024-11-21 14:21 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208273
|
5.5 |
MEDIUM
Local
|
uclouvain redhat fedoraproject debian
|
openjpeg enterprise_linux fedora debian_linux
|
A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow.…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-27824
|
2024-11-21 14:21 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208274
|
7.5 |
HIGH
Network
|
samba debian fedoraproject
|
samba debian_linux fedora
|
A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds me…
|
-
|
CVE-2020-27840
|
2024-11-21 14:21 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208275
|
7.8 |
HIGH
Local
|
windscribe
|
windscribe
|
All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the WindscribeService component. A low privilege user could leverage several openv…
|
CWE-269
Improper Privilege Management
|
CVE-2020-27518
|
2024-11-21 14:21 |
2021-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208276
|
7.8 |
HIGH
Local
|
pritunl
|
pritunl-client-electron
|
Pritunl Client v1.2.2550.20 contains a local privilege escalation vulnerability in the pritunl-service component. The attack vector is: malicious openvpn config. A local attacker could leverage the l…
|
CWE-269
Improper Privilege Management
|
CVE-2020-27519
|
2024-11-21 14:21 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208277
|
7.5 |
HIGH
Network
|
aviatrix
|
openvpn
|
Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the sys…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-27569
|
2024-11-21 14:21 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208278
|
7.5 |
HIGH
Network
|
aviatrix
|
controller
|
Insecure File Permissions exist in Aviatrix Controller 5.3.1516. Several world writable files and directories were found in the controller resource. Note: All Aviatrix appliances are fully encrypted.…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-27568
|
2024-11-21 14:21 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208279
|
7.4 |
HIGH
Network
|
siemens
|
simotics_connect_400_firmware nucleus_net nucleus_source_code nucleus_readystart_v3 nucleus_readystart_v4
|
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-27738
|
2024-11-21 14:21 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208280
|
6.5 |
MEDIUM
Network
|
siemens
|
simotics_connect_400_firmware nucleus_net nucleus_source_code nucleus_readystart_v3 nucleus_readystart_v4
|
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-27737
|
2024-11-21 14:21 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|