|
196311
|
9.8 |
CRITICAL
Network
|
freebsd
|
freebsd
|
In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE before r360971, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, libalias does not properly validate packet length resulting…
|
CWE-20 CWE-787
Improper Input Validation Out-of-bounds Write
|
CVE-2020-7454
|
2024-11-21 14:37 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196312
|
5.3 |
MEDIUM
Network
|
jooby
|
jooby
|
All versions before 1.6.7 and all versions after 2.0.0 inclusive and before 2.8.2 of io.jooby:jooby and org.jooby:jooby are vulnerable to Directory Traversal via two separate vectors.
|
CWE-22
Path Traversal
|
CVE-2020-7647
|
2024-11-21 14:37 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196313
|
7.8 |
HIGH
Local
|
mcafee
|
active_response
|
Privilege Escalation vulnerability in McAfee Active Response (MAR) for Mac prior to 2.4.3 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been…
|
CWE-269
Improper Privilege Management
|
CVE-2020-7291
|
2024-11-21 14:37 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196314
|
9.8 |
CRITICAL
Network
|
infomark
|
iml500_firmware iml520_firmware
|
An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This issue is a command injection allowing attackers to execute arbitrary OS commands.
|
CWE-78
OS Command
|
CVE-2020-7805
|
2024-11-21 14:37 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196315
|
8.8 |
HIGH
Network
|
imgtech
|
zoneplayer
|
IMGTech Co,Ltd ZInsX.ocx ActiveX Control in Zoneplayer 2.0.1.3, version 2.0.1.4 and prior versions on Windows. File Donwload vulnerability in ZInsX.ocx of IMGTech Co,Ltd Zoneplayer allows attacker to…
|
NVD-CWE-noinfo
|
CVE-2020-7803
|
2024-11-21 14:37 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196316
|
9.8 |
CRITICAL
Network
|
curlrequest_project
|
curlrequest
|
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
|
CWE-78
OS Command
|
CVE-2020-7646
|
2024-11-21 14:37 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196317
|
7.5 |
HIGH
Network
|
citrix
|
sharefile_storagezones_controller
|
In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, allow unauthenticated attackers to acces…
|
CWE-22
Path Traversal
|
CVE-2020-7473
|
2024-11-21 14:37 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196318
|
9.8 |
CRITICAL
Network
|
tobesoft
|
xplatform
|
Tobesoft Xplatform 9.2.2.250 and earlier version have an arbitrary code execution vulnerability by using method supported by Xplatform ActiveX Control. It allows attacker to cause remote code executi…
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-7806
|
2024-11-21 14:37 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196319
|
9.8 |
CRITICAL
Network
|
google
|
chrome-launcher
|
All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in Linux operating systems.
|
CWE-78
OS Command
|
CVE-2020-7645
|
2024-11-21 14:37 |
2020-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196320
|
8.8 |
HIGH
Network
|
netfortris
|
trixbox
|
An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operating system as the "a…
|
CWE-78
OS Command
|
CVE-2020-7351
|
2024-11-21 14:37 |
2020-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|