|
209491
|
9.8 |
CRITICAL
Network
|
airforce
|
nitf_extract_utility
|
U.S. Air Force Sensor Data Management System extract75 has a buffer overflow that leads to code execution. An overflow in a global variable (sBuffer) leads to a Write-What-Where outcome. Writing beyo…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13995
|
2024-11-21 14:02 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209492
|
7.5 |
HIGH
Network
|
jerryscript
|
jerryscript
|
vm/opcodes.c in JerryScript 2.2.0 allows attackers to hijack the flow of control by controlling a register.
|
NVD-CWE-noinfo
|
CVE-2020-13991
|
2024-11-21 14:02 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209493
|
7.2 |
HIGH
Network
|
ozeki
|
ozeki_ng_sms_gateway
|
An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The outbox functionality of the TXT File module can be used to delete all/most files in a folder. Because the product usually runs as N…
|
NVD-CWE-noinfo
|
CVE-2020-14031
|
2024-11-21 14:02 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209494
|
7.2 |
HIGH
Network
|
ozeki
|
ozeki_ng_sms_gateway
|
An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. By leveraging a path traversal vulnerability in the Autoreply module's Script Name, an attacker may write to or overwrite arbitrary fil…
|
CWE-22
Path Traversal
|
CVE-2020-14028
|
2024-11-21 14:02 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209495
|
5.3 |
MEDIUM
Network
|
ozeki
|
ozeki_ng_sms_gateway
|
An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The database connection strings accept custom unsafe arguments, such as ENABLE_LOCAL_INFILE, that can be leveraged by attackers to enab…
|
CWE-88
Argument Injection
|
CVE-2020-14027
|
2024-11-21 14:02 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209496
|
8.8 |
HIGH
Network
|
ozeki
|
ozeki_ng_sms_gateway
|
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS Gateway through 4.17.6 via a value that is mishandled in a CSV export.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-14026
|
2024-11-21 14:02 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209497
|
8.8 |
HIGH
Network
|
ozeki
|
ozeki_ng_sms_gateway
|
Ozeki NG SMS Gateway through 4.17.6 has multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as installing new modules o…
|
CWE-352
Origin Validation Error
|
CVE-2020-14025
|
2024-11-21 14:02 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209498
|
6.1 |
MEDIUM
Network
|
ozeki
|
ozeki_ng_sms_gateway
|
Ozeki NG SMS Gateway through 4.17.6 has multiple authenticated stored and/or reflected XSS vulnerabilities via the (1) Receiver or Recipient field in the Mailbox feature, (2) OZFORM_GROUPNAME field i…
|
CWE-79
Cross-site Scripting
|
CVE-2020-14024
|
2024-11-21 14:02 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209499
|
4.9 |
MEDIUM
Network
|
ozeki
|
ozeki_ng_sms_gateway
|
Ozeki NG SMS Gateway through 4.17.6 allows SSRF via SMS WCF or RSS To SMS.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-14023
|
2024-11-21 14:02 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209500
|
8.8 |
HIGH
Network
|
ozeki
|
ozeki_ng_sms_gateway
|
Ozeki NG SMS Gateway 4.17.1 through 4.17.6 does not check the file type when bulk importing new contacts ("Import Contacts" functionality) from a file. It is possible to upload an executable or .bat …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-14022
|
2024-11-21 14:02 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|