|
209571
|
7.1 |
HIGH
Network
|
gnome
|
libcroco
|
libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.
|
CWE-674
Uncontrolled Recursion
|
CVE-2020-12825
|
2024-11-21 14:00 |
2020-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209572
|
9.8 |
CRITICAL
Network
|
infradead fedoraproject debian opensuse
|
openconnect fedora debian_linux leap
|
OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-12823
|
2024-11-21 14:00 |
2020-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209573
|
7.5 |
HIGH
Network
|
nystudio107
|
seomatic
|
In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does not properly sanitize the URL. This leads to Server-Side Template Injection and credentials disclosure via a crafted T…
|
CWE-74
Injection
|
CVE-2020-12790
|
2024-11-21 14:00 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209574
|
8.1 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 86.0.14 allows attackers to obtain access to the current working directory via the account backup feature (SEC-540).
|
NVD-CWE-noinfo
|
CVE-2020-12785
|
2024-11-21 14:00 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209575
|
5.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 86.0.14 allows remote attackers to trigger a bandwidth suspension via mail log strings (SEC-505).
|
NVD-CWE-noinfo
|
CVE-2020-12784
|
2024-11-21 14:00 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209576
|
8.8 |
HIGH
Network
|
opennms
|
opennms_horizon opennms_meridian
|
An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The ActiveMQ channel configuration allowed for arbitrary deserialization of Java obje…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-12760
|
2024-11-21 14:00 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209577
|
7.8 |
HIGH
Local
|
google
|
android
|
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A crafted application can obtain control of device input via the window system service. The LG ID is LV…
|
NVD-CWE-noinfo
|
CVE-2020-12754
|
2024-11-21 14:00 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209578
|
9.8 |
CRITICAL
Network
|
google
|
android
|
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Arbitrary code execution can occur via the bootloader because of an EL1/EL3 coldboot vulnerability invo…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12753
|
2024-11-21 14:00 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209579
|
7.5 |
HIGH
Network
|
google
|
android
|
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. Attackers can determine user credentials via a brute-force attack against the Gatekeeper trustlet. T…
|
CWE-20 CWE-307
Improper Input Validation mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-12752
|
2024-11-21 14:00 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209580
|
7.8 |
HIGH
Local
|
google
|
android
|
An issue was discovered on Samsung mobile devices with O(8.X), P(9.0), and Q(10.0) software. The Quram image codec library allows attackers to overwrite memory and execute arbitrary code via crafted …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12751
|
2024-11-21 14:00 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|