|
196401
|
8.8 |
HIGH
Network
|
polarisoffice
|
polaris_ml_report
|
An issue was discovered in ML Report Program. There is a stack-based buffer overflow in function sub_41EAF0 at MLReportDeamon.exe. The function will call vsprintf without checking the length of strin…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7837
|
2024-11-21 14:37 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196402
|
7.5 |
HIGH
Network
|
i18n_project
|
i18n
|
This affects the package i18n before 2.1.15. Vulnerability arises out of insufficient handling of erroneous language tags in src/i18n/Concrete/TextLocalizer.cs and src/i18n/LocalizedApplication.cs.
|
NVD-CWE-noinfo
|
CVE-2020-7791
|
2024-11-21 14:37 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196403
|
7.5 |
HIGH
Network
|
ua-parser-js_project siemens
|
ua-parser-js sinec_ins
|
The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).
|
NVD-CWE-Other
|
CVE-2020-7793
|
2024-11-21 14:37 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196404
|
7.5 |
HIGH
Network
|
moutjs
|
mout
|
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn 'mixes objects into the target object, recursively mixing …
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7792
|
2024-11-21 14:37 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196405
|
5.3 |
MEDIUM
Network
|
spatie
|
browsershot
|
This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF.
|
CWE-22
Path Traversal
|
CVE-2020-7790
|
2024-11-21 14:37 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196406
|
9.8 |
CRITICAL
Network
|
ini_project debian
|
ini debian_linux
|
This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7788
|
2024-11-21 14:37 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196407
|
5.6 |
MEDIUM
Network
|
node-notifier_project
|
node-notifier
|
This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines due to the options params not being sanitised when being passed an array.
|
CWE-78
OS Command
|
CVE-2020-7789
|
2024-11-21 14:37 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196408
|
8.6 |
HIGH
Local
|
schneider-electric
|
unity_pro ecostruxure_control_expert
|
A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Control Expert (all versions) and Unity Pro (former name of EcoStruxure™ Control Expert) (all versions), that could cause a …
|
-
|
CVE-2020-7560
|
2024-11-21 14:37 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196409
|
5.3 |
MEDIUM
Network
|
schneider-electric
|
modicon_m340_bmxp341000_firmware modicon_m340_bmxp342000_firmware modicon_m340_bmxp3420102_firmware modicon_m340_bmxp3420102cl_firmware modicon_m340_bmxp342020_firmware modicon_m340_bm…
|
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication …
|
-
|
CVE-2020-7549
|
2024-11-21 14:37 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196410
|
7.5 |
HIGH
Network
|
schneider-electric
|
modicon_m580_bmep584040_firmware modicon_m580_bmep582040_firmware modicon_m580_bmep586040_firmware modicon_m580_bmep585040_firmware modicon_m580_bmep582020_firmware modicon_m580_bmep58…
|
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications fo…
|
-
|
CVE-2020-7543
|
2024-11-21 14:37 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|