|
198601
|
6.1 |
MEDIUM
Local
|
gnu fedoraproject netapp broadcom
|
binutils fedora cloud_backup ontap_select_deploy_administration_utility solidfire_\&_hci_management_node solidfire\ _enterprise_sds_\&_hci_storage_node brocade_fabric_ope…
|
There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to…
|
-
|
CVE-2020-35494
|
2024-11-21 14:27 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198602
|
5.5 |
MEDIUM
Local
|
gnu fedoraproject netapp broadcom
|
binutils fedora cloud_backup ontap_select_deploy_administration_utility solidfire_\&_hci_management_node solidfire\ _enterprise_sds_\&_hci_storage_node brocade_fabric_ope…
|
A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an imp…
|
-
|
CVE-2020-35493
|
2024-11-21 14:27 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198603
|
9.0 |
CRITICAL
Network
|
electronjs
|
zonote
|
zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).
|
CWE-79
Cross-site Scripting
|
CVE-2020-35717
|
2024-11-21 14:27 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198604
|
6.5 |
MEDIUM
Adjacent
|
tenda
|
f3_firmware
|
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2020-35391
|
2024-11-21 14:27 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198605
|
7.6 |
HIGH
Network
|
hgiga
|
msr45_isherlock-antispam msr45_isherlock-user ssr45_isherlock-antispam ssr45_isherlock-user
|
HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.
|
CWE-89
SQL Injection
|
CVE-2020-35743
|
2024-11-21 14:27 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198606
|
7.6 |
HIGH
Network
|
hgiga
|
msr45_isherlock-antispam msr45_isherlock-user ssr45_isherlock-antispam ssr45_isherlock-user
|
HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.
|
CWE-89
SQL Injection
|
CVE-2020-35742
|
2024-11-21 14:27 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198607
|
6.1 |
MEDIUM
Network
|
hgiga
|
msr45_isherlock-antispam msr45_isherlock-user ssr45_isherlock-antispam ssr45_isherlock-user
|
HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35741
|
2024-11-21 14:27 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198608
|
6.1 |
MEDIUM
Network
|
hgiga
|
msr45_isherlock-antispam msr45_isherlock-user ssr45_isherlock-antispam ssr45_isherlock-user
|
HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35740
|
2024-11-21 14:27 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198609
|
7.5 |
HIGH
Network
|
newgensoft
|
egov
|
In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Objec…
|
NVD-CWE-Other
|
CVE-2020-35737
|
2024-11-21 14:27 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198610
|
4.8 |
MEDIUM
Network
|
flatpress
|
flatpress
|
FlatPress 1.0.3 is affected by cross-site scripting (XSS) in the Blog Content component. This vulnerability can allow an attacker to inject the XSS payload in Blog content via the admin panel. Each t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35241
|
2024-11-21 14:27 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|