|
208241
|
6.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The Linux kernel through 5.8.13 does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protection mechanism. This affects certs/blacklist.c and certs/system_keyring.c.
|
NVD-CWE-Other
|
CVE-2020-26541
|
2024-11-21 14:20 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208242
|
7.5 |
HIGH
Network
|
foxitsoftware
|
foxit_reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mechanism is not applied to code signing, code injection (or an information leak) c…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-26540
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208243
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
foxit_reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. When there is a multiple interpretation error for /V (in the Additional Action and Field dictionaries), a use-after-free can occur …
|
CWE-416
Use After Free
|
CVE-2020-26539
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208244
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. It allows attackers to execute arbitrary code via a Trojan horse taskkill.exe in the current working directory.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-26538
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208245
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
foxit_reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. In a certain Shading calculation, the number of outputs is unequal to the number of color components in a color space. This causes …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-26537
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208246
|
5.5 |
MEDIUM
Local
|
foxitsoftware
|
foxit_reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is a NULL pointer dereference via a crafted PDF document.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-26536
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208247
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
foxit_reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate thread local storage but obtains an unacceptable index value, V8 throws an exception that leads to…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-26535
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208248
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
foxit_reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::DeleteOptions, during AcroForm JavaScript execution.
|
CWE-416
Use After Free
|
CVE-2020-26534
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208249
|
5.3 |
MEDIUM
Network
|
filecloud
|
filecloud
|
CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.
|
NVD-CWE-noinfo
|
CVE-2020-26524
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208250
|
6.1 |
MEDIUM
Network
|
froala
|
froala_editor
|
Froala Editor before 3.2.2 allows XSS via pasted content.
|
CWE-79
Cross-site Scripting
|
CVE-2020-26523
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|