|
208211
|
9.8 |
CRITICAL
Network
|
foldingathome
|
client_advanced_control
|
An issue was discovered in FoldingAtHome Client Advanced Control GUI before commit 9b619ae64443997948a36dda01b420578de1af77, allows remote attackers to execute arbitrary code via crafted payload to f…
|
NVD-CWE-noinfo
|
CVE-2020-27544
|
2024-11-21 14:21 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208212
|
9.1 |
CRITICAL
Network
|
zrlog
|
zrlog
|
Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attackers to delete arbitrary files and cause a denial of service (DoS).
|
CWE-22
Path Traversal
|
CVE-2020-27514
|
2024-11-21 14:21 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208213
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_password_manager_pro
|
Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via craft…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27449
|
2024-11-21 14:21 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208214
|
6.5 |
MEDIUM
Network
|
libdwarf_project
|
libdwarf
|
libdwarf before 20201017 has a one-byte out-of-bounds read because of an invalid pointer dereference via an invalid line table in a crafted object.
|
CWE-763
Release of Invalid Pointer or Reference
|
CVE-2020-27545
|
2024-11-21 14:21 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208215
|
9.8 |
CRITICAL
Network
|
bigbluebutton
|
bigbluebutton
|
BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.
|
CWE-74
Injection
|
CVE-2020-27602
|
2024-11-21 14:21 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208216
|
3.5 |
LOW
Network
|
bigbluebutton
|
bigbluebutton
|
In BigBlueButton before 2.2.7, lockSettingsProps.disablePrivateChat does not apply to already opened chats. This occurs in bigbluebutton-html5/imports/ui/components/chat/service.js.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-27601
|
2024-11-21 14:21 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208217
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
A vulnerability was found in the Linux kernel, where accessing a deallocated instance in printer_ioctl() printer_ioctl() tries to access of a printer_dev instance. However, use-after-free arises beca…
|
CWE-416
Use After Free
|
CVE-2020-27784
|
2024-11-21 14:21 |
2022-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208218
|
5.5 |
MEDIUM
Local
|
upx_project
|
upx
|
An floating point exception was discovered in the elf_lookup function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.
|
CWE-369
Divide By Zero
|
CVE-2020-27802
|
2024-11-21 14:21 |
2022-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208219
|
7.8 |
HIGH
Local
|
upx_project
|
upx
|
A heap-based buffer over-read was discovered in the get_le64 function in bele.h in UPX 4.0.0 via a crafted Mach-O file.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-27801
|
2024-11-21 14:21 |
2022-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208220
|
7.8 |
HIGH
Local
|
upx_project
|
upx
|
A heap-based buffer over-read was discovered in the get_le32 function in bele.h in UPX 4.0.0 via a crafted Mach-O file.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-27800
|
2024-11-21 14:21 |
2022-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|