|
208341
|
7.5 |
HIGH
Network
|
facebook
|
hhvm
|
The fb_unserialize function did not impose a depth limit for nested deserialization. That meant a maliciously constructed string could cause deserialization to recurse, leading to stack exhaustion. T…
|
CWE-674
Uncontrolled Recursion
|
CVE-2020-1898
|
2024-11-21 14:11 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208342
|
7.5 |
HIGH
Network
|
facebook
|
hhvm
|
In the crypt function, we attempt to null terminate a buffer using the size of the input salt without validating that the offset is within the buffer. This issue affects HHVM versions prior to 4.56.3…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-1921
|
2024-11-21 14:11 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208343
|
7.5 |
HIGH
Network
|
facebook
|
hhvm
|
Incorrect bounds calculations in substr_compare could lead to an out-of-bounds read when the second string argument passed in is longer than the first. This issue affects HHVM versions prior to 4.56.…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-1919
|
2024-11-21 14:11 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208344
|
7.5 |
HIGH
Network
|
facebook
|
hhvm
|
In-memory file operations (ie: using fopen on a data URI) did not properly restrict negative seeking, allowing for the reading of memory prior to the in-memory buffer. This issue affects HHVM version…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-1918
|
2024-11-21 14:11 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208345
|
9.8 |
CRITICAL
Network
|
facebook
|
hhvm
|
xbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to the generated string, but was not using its standard append char function. As a result, if the buf…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-1917
|
2024-11-21 14:11 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208346
|
9.8 |
CRITICAL
Network
|
facebook
|
hhvm
|
An incorrect size calculation in ldap_escape may lead to an integer overflow when overly long input is passed in, resulting in an out-of-bounds write. This issue affects HHVM prior to 4.56.2, all ver…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-1916
|
2024-11-21 14:11 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208347
|
6.1 |
MEDIUM
Network
|
apache
|
ambari
|
A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.
|
CWE-79
Cross-site Scripting
|
CVE-2020-1936
|
2024-11-21 14:11 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208348
|
2.7 |
LOW
Network
|
redhat
|
keycloak single_sign-on jboss_fuse openshift_application_runtimes
|
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-1717
|
2024-11-21 14:11 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208349
|
4.9 |
MEDIUM
Network
|
otrs
|
ticket_forms
|
When dynamic templates are used (OTRSTicketForms), admin can use OTRS tags which are not masked properly and can reveal sensitive information. This issue affects: OTRS AG OTRSTicketForms 6.0.x versio…
|
CWE-200
Information Exposure
|
CVE-2020-1779
|
2024-11-21 14:11 |
2021-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208350
|
7.8 |
HIGH
Local
|
whatsapp
|
whatsapp_business whatsapp
|
A missing bounds check in WhatsApp for Android prior to v2.21.1.13 and WhatsApp Business for Android prior to v2.21.1.13 could have allowed out-of-bounds read and write if a user applied specific ima…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-1910
|
2024-11-21 14:11 |
2021-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|