|
196401
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm through 4.19.96 (and 5.x before 5.2), there is a use-after-free (write) in the i915_ppgtt_close function in drivers/gpu/drm/i915/i…
|
CWE-416
Use After Free
|
CVE-2020-7053
|
2024-11-21 14:36 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196402
|
9.1 |
CRITICAL
Network
|
yet_another_java_service_wrapper_project
|
yet_another_java_service_wrapper
|
An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially …
|
CWE-611
XXE
|
CVE-2020-6958
|
2024-11-21 14:36 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196403
|
6.1 |
MEDIUM
Network
|
cayintech
|
smp-pro4_firmware
|
An issue was discovered on Cayin SMP-PRO4 devices. They allow image_preview.html?filename= reflected XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-6955
|
2024-11-21 14:36 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196404
|
6.5 |
MEDIUM
Network
|
cayintech
|
smp-pro4_firmware
|
An issue was discovered on Cayin SMP-PRO4 devices. A user can discover a saved password by viewing the URL after a Connection String Test. This password is shown in the webpass parameter of a media_f…
|
CWE-200
Information Exposure
|
CVE-2020-6954
|
2024-11-21 14:36 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196405
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was possible for someone to obtain issues from private projects.
|
NVD-CWE-noinfo
|
CVE-2020-6832
|
2024-11-21 14:36 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196406
|
8.8 |
HIGH
Network
|
hashbrowncms
|
hashbrown_cms
|
A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can change the password hash of an admin user's account, or otherwise reconfigure t…
|
CWE-269
Improper Privilege Management
|
CVE-2020-6949
|
2024-11-21 14:36 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196407
|
9.8 |
CRITICAL
Network
|
hashbrowncms
|
hashbrown_cms
|
A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a Service.AppService.exec call that mishandles the URL, repository, username, an…
|
CWE-78
OS Command
|
CVE-2020-6948
|
2024-11-21 14:36 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196408
|
5.3 |
MEDIUM
Network
|
ultimatemember
|
ultimate_member
|
Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' prof…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-6859
|
2024-11-21 14:36 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196409
|
8.8 |
HIGH
Network
|
symonics fedoraproject
|
libmysofa fedora
|
libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6860
|
2024-11-21 14:36 |
2020-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196410
|
7.5 |
HIGH
Network
|
uclouvain fedoraproject debian redhat oracle
|
openjpeg fedora debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux enterprise_linux_server_aus enterprise_linux_server…
|
OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6851
|
2024-11-21 14:36 |
2020-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|