|
209441
|
4.8 |
MEDIUM
Network
|
mutt canonical
|
mutt ubuntu_linux
|
Mutt before 1.14.3 proceeds with a connection even if, in response to a GnuTLS certificate prompt, the user rejects an expired intermediate certificate.
|
NVD-CWE-Other
|
CVE-2020-14154
|
2024-11-21 14:02 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209442
|
7.1 |
HIGH
Local
|
ijg
|
libjpeg
|
In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for certain table pointers.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-14153
|
2024-11-21 14:02 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209443
|
7.1 |
HIGH
Local
|
ijg debian
|
libjpeg debian_linux
|
In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-14152
|
2024-11-21 14:02 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209444
|
5.5 |
MEDIUM
Local
|
gnu
|
bison
|
GNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash). NOTE: there is a risk only if Bison is used with untrusted input, and an observed bug happens to cause unsafe…
|
NVD-CWE-noinfo
|
CVE-2020-14150
|
2024-11-21 14:02 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209445
|
9.8 |
CRITICAL
Network
|
meetecho
|
janus
|
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c has a Buffer Overflow via long value in an SDP Offer packet.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-14034
|
2024-11-21 14:02 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209446
|
9.8 |
CRITICAL
Network
|
meetecho
|
janus
|
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_streaming_rtsp_parse_sdp in plugins/janus_streaming.c has a Buffer Overflow via a crafted RTSP server.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-14033
|
2024-11-21 14:02 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209447
|
9.8 |
CRITICAL
Network
|
sokkia
|
gnr5_vanguard_firmware
|
SOKKIA GNR5 Vanguard WEB version 1.2 (build: 91f2b2c3a04d203d79862f87e2440cb7cefc3cd3) and hardware version 212 allows remote attackers to bypass admin authentication via a SQL injection attack that …
|
CWE-89
SQL Injection
|
CVE-2020-14054
|
2024-11-21 14:02 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209448
|
5.5 |
MEDIUM
Local
|
libemf_project fedoraproject
|
libemf fedora
|
ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer overflow and denial of service via a crafted EMF file.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-13999
|
2024-11-21 14:02 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209449
|
9.8 |
CRITICAL
Network
|
lansweeper
|
lansweeper
|
Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is manually unchecked. This allows command execution…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2020-14011
|
2024-11-21 14:02 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209450
|
5.4 |
MEDIUM
Network
|
kumbiaphp
|
kumbiaphp
|
KumbiaPHP through 1.1.1, in Development mode, allows XSS via the public/pages/kumbia PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2020-14146
|
2024-11-21 14:02 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|