|
198411
|
9.8 |
CRITICAL
Network
|
clusterlabs
|
hawk
|
An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in the login_from_cookie cookie. The user logout rout…
|
CWE-78
OS Command
|
CVE-2020-35458
|
2024-11-21 14:27 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198412
|
5.4 |
MEDIUM
Network
|
python fedoraproject
|
pillow fedora
|
In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-35655
|
2024-11-21 14:27 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198413
|
8.8 |
HIGH
Network
|
python fedoraproject
|
pillow fedora
|
In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35654
|
2024-11-21 14:27 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198414
|
7.1 |
HIGH
Network
|
python fedoraproject debian
|
pillow fedora debian_linux
|
In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffer calculations.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-35653
|
2024-11-21 14:27 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198415
|
8.8 |
HIGH
Network
|
cacti fedoraproject
|
cacti fedora
|
An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execute arbitrary SQL commands via the site_id paramete…
|
CWE-89
SQL Injection
|
CVE-2020-35701
|
2024-11-21 14:27 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198416
|
7.8 |
HIGH
Local
|
anydesk
|
anydesk
|
AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local user account via a …
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-35483
|
2024-11-21 14:27 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198417
|
5.4 |
MEDIUM
Network
|
quest
|
policy_authority_for_unified_communications
|
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the BrowseDirs.do file via the title parameter. NOT…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35727
|
2024-11-21 14:27 |
2021-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198418
|
6.1 |
MEDIUM
Network
|
quest
|
policy_authority_for_unified_communications
|
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/Applications/Reports/index.jsp file via …
|
CWE-79
Cross-site Scripting
|
CVE-2020-35726
|
2024-11-21 14:27 |
2021-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198419
|
6.1 |
MEDIUM
Network
|
quest
|
policy_authority_for_unified_communications
|
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/index.jsp file via the msg parameter. NO…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35725
|
2024-11-21 14:27 |
2021-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198420
|
5.4 |
MEDIUM
Network
|
quest
|
policy_authority_for_unified_communications
|
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the Error.jsp file via the err parameter (or indire…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35724
|
2024-11-21 14:27 |
2021-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|