|
197851
|
9.1 |
CRITICAL
Network
|
webmproject redhat netapp debian apple
|
libwebp enterprise_linux ontap_select_deploy_administration_utility debian_linux iphone_os ipados
|
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the ser…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-36331
|
2024-11-21 14:29 |
2021-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197852
|
9.1 |
CRITICAL
Network
|
webmproject debian redhat netapp apple
|
libwebp debian_linux enterprise_linux ontap_select_deploy_administration_utility iphone_os ipados
|
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to th…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-36330
|
2024-11-21 14:29 |
2021-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197853
|
9.8 |
CRITICAL
Network
|
webmproject redhat netapp debian apple
|
libwebp enterprise_linux ontap_select_deploy_administration_utility debian_linux iphone_os ipados
|
A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and inte…
|
CWE-416
Use After Free
|
CVE-2020-36329
|
2024-11-21 14:29 |
2021-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197854
|
9.8 |
CRITICAL
Network
|
webmproject redhat netapp debian apple
|
libwebp enterprise_linux ontap_select_deploy_administration_utility debian_linux ipados iphone_os
|
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vuln…
|
-
|
CVE-2020-36328
|
2024-11-21 14:29 |
2021-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197855
|
6.1 |
MEDIUM
Network
|
smartstore
|
smartstorenet
|
Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Edit open redirect.
|
CWE-601
Open Redirect
|
CVE-2020-36365
|
2024-11-21 14:29 |
2021-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197856
|
9.1 |
CRITICAL
Network
|
smartstore
|
smartstorenet
|
An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs allows path traversal (for copy and delete actions) in the ImportController.Crea…
|
CWE-22
Path Traversal
|
CVE-2020-36364
|
2024-11-21 14:29 |
2021-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197857
|
6.7 |
MEDIUM
Local
|
qnap
|
malware_remover
|
A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue a…
|
CWE-78
OS Command
|
CVE-2020-36198
|
2024-11-21 14:29 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197858
|
5.3 |
MEDIUM
Network
|
atlassian
|
data_center jira jira_server jira_data_center
|
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa…
|
CWE-863
Incorrect Authorization
|
CVE-2020-36289
|
2024-11-21 14:29 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197859
|
8.8 |
HIGH
Network
|
themegrill
|
themegrill_demo_importer
|
themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.
|
CWE-352
Origin Validation Error
|
CVE-2020-36334
|
2024-11-21 14:29 |
2021-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197860
|
9.1 |
CRITICAL
Network
|
themegrill
|
themegrill_demo_importer
|
themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-36333
|
2024-11-21 14:29 |
2021-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|