|
209561
|
8.8 |
HIGH
Network
|
liferay
|
liferay_portal
|
In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not restrict user access to sensitive objects, which al…
|
CWE-74 CWE-862
Injection Missing Authorization
|
CVE-2020-13445
|
2024-11-21 14:01 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209562
|
6.5 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which…
|
NVD-CWE-noinfo
|
CVE-2020-13444
|
2024-11-21 14:01 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209563
|
5.5 |
MEDIUM
Local
|
arm opensuse
|
cortex-a32_firmware cortex-a35_firmware cortex-a53_firmware cortex-a57_firmware cortex-a72_firmware cortex-a73_firmware cortex-a34_firmware leap
|
Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via …
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-13844
|
2024-11-21 14:01 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209564
|
7.8 |
HIGH
Local
|
videolan debian
|
vlc_media_player debian_linux
|
A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13428
|
2024-11-21 14:01 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209565
|
7.5 |
HIGH
Network
|
rejetto
|
http_file_server
|
rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access violation via concurrent HTTP requests …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-13432
|
2024-11-21 14:01 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209566
|
4.4 |
MEDIUM
Local
|
linuxtv debian opensuse fedoraproject canonical
|
xawtv debian_linux leap backports_sle fedora ubuntu_linux
|
An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintende…
|
CWE-863
Incorrect Authorization
|
CVE-2020-13696
|
2024-11-21 14:01 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209567
|
7.5 |
HIGH
Network
|
phpmailer_project fedoraproject canonical debian
|
phpmailer fedora ubuntu_linux debian_linux
|
PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or a…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2020-13625
|
2024-11-21 14:01 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209568
|
7.8 |
HIGH
Local
|
ijinshan
|
cheetah_free_wifi
|
In Cheetah free WiFi 5.1, the driver file (liebaonat.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from …
|
CWE-20
Improper Input Validation
|
CVE-2020-13646
|
2024-11-21 14:01 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209569
|
5.5 |
MEDIUM
Local
|
google
|
android
|
An issue was discovered on LG mobile devices with Android OS software before 2020-06-01. Local users can cause a denial of service because checking of the userdata partition is mishandled. The LG ID …
|
NVD-CWE-noinfo
|
CVE-2020-13843
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209570
|
7.8 |
HIGH
Local
|
google
|
android
|
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). A dangerous AT command was made available even though it is unused. The LG ID is LVE-SMP-200010 (…
|
NVD-CWE-noinfo
|
CVE-2020-13842
|
2024-11-21 14:01 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|