|
208691
|
5.3 |
MEDIUM
Network
|
soplanning
|
soplanning
|
SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without authentication.
|
CWE-287
Improper Authentication
|
CVE-2020-25867
|
2024-11-21 14:18 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208692
|
5.3 |
MEDIUM
Network
|
contao
|
contao
|
Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end forms which will be replaced when the page is rend…
|
CWE-20 CWE-74
Improper Input Validation Injection
|
CVE-2020-25768
|
2024-11-21 14:18 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208693
|
7.5 |
HIGH
Network
|
wireshark fedoraproject opensuse oracle
|
wireshark fedora leap zfs_storage_appliance_kit
|
In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed i…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-25866
|
2024-11-21 14:18 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208694
|
7.5 |
HIGH
Network
|
wireshark fedoraproject opensuse debian oracle
|
wireshark fedora leap debian_linux zfs_storage_appliance_firmware
|
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of…
|
NVD-CWE-noinfo
|
CVE-2020-25863
|
2024-11-21 14:18 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208695
|
7.5 |
HIGH
Network
|
wireshark fedoraproject opensuse debian oracle
|
wireshark fedora leap debian_linux zfs_storage_appliance_firmware
|
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF che…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-25862
|
2024-11-21 14:18 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208696
|
7.2 |
HIGH
Network
|
craftercms
|
studio
|
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker template exposed objects. T…
|
CWE-913
Improper Control of Dynamically-Managed Code Resources
|
CVE-2020-25803
|
2024-11-21 14:18 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208697
|
3.2 |
LOW
Local
|
qemu redhat
|
qemu enterprise_linux openstack_platform
|
hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-25743
|
2024-11-21 14:18 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208698
|
3.2 |
LOW
Local
|
qemu
|
qemu
|
pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-25742
|
2024-11-21 14:18 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208699
|
7.2 |
HIGH
Network
|
craftercms
|
studio
|
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy scripting. This issue affects: …
|
CWE-913
Improper Control of Dynamically-Managed Code Resources
|
CVE-2020-25802
|
2024-11-21 14:18 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208700
|
7.5 |
HIGH
Network
|
redhat netapp
|
wildfly_openssl jboss_enterprise_application_platform single_sign-on jboss_fuse jboss_data_grid openshift_application_runtimes data_grid oncommand_workflow_automation oncomman…
|
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest …
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-25644
|
2024-11-21 14:18 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|