|
198461
|
9.8 |
CRITICAL
Network
|
flamingo_project
|
flamingo
|
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addGroup.
|
CWE-89
SQL Injection
|
CVE-2020-35244
|
2024-11-21 14:27 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198462
|
9.8 |
CRITICAL
Network
|
flamingo_project
|
flamingo
|
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserInfoInDb.
|
CWE-89
SQL Injection
|
CVE-2020-35243
|
2024-11-21 14:27 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198463
|
9.8 |
CRITICAL
Network
|
flamingo_project
|
flamingo
|
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserTeamInfoInDbAndMemory.
|
CWE-89
SQL Injection
|
CVE-2020-35242
|
2024-11-21 14:27 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198464
|
9.8 |
CRITICAL
Network
|
huorong
|
internet_security
|
Beijing Huorong Internet Security 5.0.55.2 allows a non-admin user to escalate privileges by injecting code into a process, and then waiting for a Huorong services restart or a system reboot.
|
NVD-CWE-noinfo
|
CVE-2020-35364
|
2024-11-21 14:27 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198465
|
7.5 |
HIGH
Network
|
dext5
|
dext5upload
|
DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow remote files to be downloaded via a dext5CMD=downloadRequest action with traversal…
|
CWE-22
Path Traversal
|
CVE-2020-35362
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198466
|
7.5 |
HIGH
Network
|
flamingoim_project
|
flamingoim
|
Flamingo (aka FlamingoIM) through 2020-09-29 allows ../ directory traversal because the only ostensibly unpredictable part of a file-transfer request is an MD5 computation; however, this computation …
|
CWE-22
Path Traversal
|
CVE-2020-35284
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198467
|
7.5 |
HIGH
Network
|
gobby_project
|
gobby
|
Gobby 0.4.11 allows a NULL pointer dereference in the D-Bus handler for certain set_language calls.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-35450
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198468
|
7.5 |
HIGH
Network
|
pureftpd
|
pure-ftpd
|
Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-35359
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198469
|
6.1 |
MEDIUM
Network
|
intelliants
|
subrion_cms
|
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35437
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198470
|
7.5 |
HIGH
Network
|
xpdfreader fedoraproject
|
xpdf fedora
|
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35376
|
2024-11-21 14:27 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|