|
209491
|
6.5 |
MEDIUM
Network
|
nchsoftware
|
express_accounts
|
In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2020-13474
|
2024-11-21 14:01 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209492
|
5.5 |
MEDIUM
Local
|
nchsoftware
|
express_accounts
|
NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-13473
|
2024-11-21 14:01 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209493
|
8.8 |
HIGH
Network
|
foxitsoftware
|
foxit_reader
|
A type confusion vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger an improper use of an object, r…
|
CWE-787 CWE-843
Out-of-bounds Write Type Confusion
|
CVE-2020-13547
|
2024-11-21 14:01 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209494
|
8.8 |
HIGH
Network
|
foxitsoftware
|
foxit_reader
|
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger the reuse of previously free memory w…
|
CWE-416
Use After Free
|
CVE-2020-13570
|
2024-11-21 14:01 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209495
|
8.8 |
HIGH
Network
|
foxitsoftware
|
foxit_reader
|
A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of previously free memory…
|
CWE-416
Use After Free
|
CVE-2020-13560
|
2024-11-21 14:01 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209496
|
8.8 |
HIGH
Network
|
foxitsoftware
|
foxit_reader
|
A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of previously free memory…
|
CWE-416
Use After Free
|
CVE-2020-13557
|
2024-11-21 14:01 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209497
|
7.8 |
HIGH
Local
|
kepware
|
linkmaster
|
A privilege escalation vulnerability exists in Kepware LinkMaster 3.0.94.0. In its default configuration, an attacker can globally overwrite service configuration to execute arbitrary code with NT SY…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13535
|
2024-11-21 14:01 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209498
|
8.8 |
HIGH
Local
|
nzxt
|
cam
|
A privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c402088 functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) can cause increased privileges. An a…
|
CWE-862
Missing Authorization
|
CVE-2020-13519
|
2024-11-21 14:01 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209499
|
8.8 |
HIGH
Local
|
nzxt
|
cam
|
A privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c40a148 functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) can cause an adversary to obtain ele…
|
CWE-862
Missing Authorization
|
CVE-2020-13515
|
2024-11-21 14:01 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209500
|
8.8 |
HIGH
Local
|
nzxt
|
cam
|
A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) can cause increased privi…
|
CWE-862
Missing Authorization
|
CVE-2020-13514
|
2024-11-21 14:01 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|