|
209641
|
7.8 |
HIGH
Local
|
logicaldoc
|
logicaldoc
|
A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depending on the vector chosen, an attacker can either replace the service binary or …
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13542
|
2024-11-21 14:01 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209642
|
8.8 |
HIGH
Network
|
pixar
|
openusd
|
A use-after-free vulnerability exists in a way Pixar OpenUSD 20.08 processes reference paths textual USD files. A specially crafted file can trigger the reuse of a freed memory which can result in fu…
|
CWE-416
Use After Free
|
CVE-2020-13531
|
2024-11-21 14:01 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209643
|
5.5 |
MEDIUM
Local
|
pixar
|
openusd
|
An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially crafted malformed file can trigger an arbitrary out of bounds memory access which …
|
-
|
CVE-2020-13498
|
2024-11-21 14:01 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209644
|
5.5 |
MEDIUM
Local
|
pixar
|
openusd
|
An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially crafted malformed file can trigger an arbitrary out of bounds memory access in Str…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-13497
|
2024-11-21 14:01 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209645
|
6.5 |
MEDIUM
Network
|
pixar
|
openusd
|
An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles parses certain encoded types. A specially crafted malformed file can trigger an arbitrary out of bounds memory access in TfT…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-13496
|
2024-11-21 14:01 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209646
|
5.5 |
MEDIUM
Local
|
pixar
|
openusd
|
A heap overflow vulnerability exists in the Pixar OpenUSD 20.05 parsing of compressed string tokens in binary USD files. A specially crafted malformed file can trigger a heap overflow which can resul…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13494
|
2024-11-21 14:01 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209647
|
7.8 |
HIGH
Local
|
pixar
|
openusd
|
A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. A specially crafted USDC file format path jumps decompression heap overfl…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13493
|
2024-11-21 14:01 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209648
|
8.8 |
HIGH
Network
|
fastweb
|
fastgate_gpon_fga2130fwb_firmware
|
Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's ability to perform administrative actions such as modifying th…
|
CWE-352
Origin Validation Error
|
CVE-2020-13620
|
2024-11-21 14:01 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209649
|
8.8 |
HIGH
Network
|
drupal fedoraproject
|
drupal fedora
|
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP f…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-13671
|
2024-11-21 14:01 |
2020-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209650
|
7.6 |
HIGH
Network
|
gitlab
|
gitlab
|
The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and ot…
|
NVD-CWE-noinfo
|
CVE-2020-13359
|
2024-11-21 14:01 |
2020-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|