|
197291
|
8.1 |
HIGH
Network
|
gnu opensuse
|
libredwg leap backports_sle
|
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-6614
|
2024-11-21 14:36 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197292
|
8.1 |
HIGH
Network
|
gnu opensuse
|
libredwg leap backports_sle
|
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-6613
|
2024-11-21 14:36 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197293
|
8.1 |
HIGH
Network
|
gnu opensuse
|
libredwg leap backports_sle
|
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-6612
|
2024-11-21 14:36 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197294
|
6.5 |
MEDIUM
Network
|
gnu opensuse
|
libredwg leap backports_sle
|
GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-6611
|
2024-11-21 14:36 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197295
|
6.5 |
MEDIUM
Network
|
gnu opensuse
|
libredwg leap backports
|
GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-6610
|
2024-11-21 14:36 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197296
|
8.8 |
HIGH
Network
|
gnu opensuse
|
libredwg leap backports_sle
|
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-6609
|
2024-11-21 14:36 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197297
|
6.1 |
MEDIUM
Network
|
bigprof
|
online_invoicing_system
|
BigProf Online Invoicing System (OIS) through 2.6 has XSS that can be leveraged for session hijacking. An attacker can exploit the XSS vulnerability, retrieve the session cookie from the administrato…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6583
|
2024-11-21 14:36 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197298
|
4.7 |
MEDIUM
Network
|
sap
|
business_objects_business_intelligence_platform
|
BI Launchpad and CMC in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerabil…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6220
|
2024-11-21 14:35 |
2022-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197299
|
7.8 |
HIGH
Local
|
graphisoft
|
bimx_desktop_viewer
|
An exploitable code execution vulnerability exists in the file format parsing functionality of Graphisoft BIMx Desktop Viewer 2019.2.2328. A specially crafted file can cause a heap buffer overflow re…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-6099
|
2024-11-21 14:35 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197300
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Use after free in ANGLE in Google Chrome prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2020-6492
|
2024-11-21 14:35 |
2021-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|