|
196851
|
9.8 |
CRITICAL
Network
|
mruby
|
mruby
|
In mruby 2.1.0, there is a use-after-free in hash_values_at in mrbgems/mruby-hash-ext/src/hash-ext.c.
|
CWE-416
Use After Free
|
CVE-2020-6838
|
2024-11-21 14:36 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196852
|
9.8 |
CRITICAL
Network
|
hot-formula-parser_project
|
hot-formula-parser
|
grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanitize values passed to the parse function and concat…
|
CWE-94
Code Injection
|
CVE-2020-6836
|
2024-11-21 14:36 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196853
|
9.8 |
CRITICAL
Network
|
bftpd_project
|
bftpd
|
An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking.
|
CWE-193
Off-by-one Error
|
CVE-2020-6835
|
2024-11-21 14:36 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196854
|
6.1 |
MEDIUM
Network
|
rasilient
|
pixelstor_5000_firmware
|
A cross-site scripting (XSS) vulnerability in Option/optionsAll.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows remote attackers to inject arbitrary web script or HTML via th…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6758
|
2024-11-21 14:36 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196855
|
8.8 |
HIGH
Network
|
rasilient
|
pixelstor_5000_firmware
|
contentHostProperties.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows authenticated attackers to remotely execute code via the name parameter.
|
CWE-78
OS Command
|
CVE-2020-6757
|
2024-11-21 14:36 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196856
|
9.8 |
CRITICAL
Network
|
rasilient
|
pixelstor_5000_firmware
|
languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the lang parameter.
|
CWE-78
OS Command
|
CVE-2020-6756
|
2024-11-21 14:36 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196857
|
5.9 |
MEDIUM
Network
|
gnome fedoraproject
|
glib fedora
|
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mis…
|
NVD-CWE-noinfo
|
CVE-2020-6750
|
2024-11-21 14:36 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196858
|
6.1 |
MEDIUM
Network
|
prestashop
|
prestashop
|
In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/default/template/header.tpl, and themes/new-theme/js…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6632
|
2024-11-21 14:36 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196859
|
5.5 |
MEDIUM
Local
|
gpac
|
gpac
|
An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_m2ts_stream_process_pmt() in media_tools/m2ts_mux.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-6631
|
2024-11-21 14:36 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196860
|
5.5 |
MEDIUM
Local
|
gpac
|
gpac
|
An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_isom_get_media_data_size() in isomedia/isom_read.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-6630
|
2024-11-21 14:36 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|