|
209511
|
7.8 |
HIGH
Local
|
freedroid
|
freedroidrpg
|
An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts that recover a game's state. A file can be modified to put any Lua code inside, l…
|
CWE-20
Improper Input Validation
|
CVE-2020-14939
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209512
|
9.8 |
CRITICAL
Network
|
freedroid
|
freedroidrpg
|
An issue was discovered in map.c in FreedroidRPG 1.0rc2. It assumes lengths of data sets read from saved game files. It copies data from a file into a fixed-size heap-allocated buffer without size ve…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-14938
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209513
|
4.3 |
MEDIUM
Network
|
globalradar
|
bsa_radar
|
downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and earlier allows users to download transaction files. When downloading the files, …
|
CWE-22
Path Traversal
|
CVE-2020-14946
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209514
|
8.8 |
HIGH
Network
|
globalradar
|
bsa_radar
|
A privilege escalation vulnerability exists within Global RADAR BSA Radar 1.6.7234.24750 and earlier that allows an authenticated, low-privileged user to escalate their privileges to administrator ri…
|
NVD-CWE-noinfo
|
CVE-2020-14945
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209515
|
9.8 |
CRITICAL
Network
|
globalradar
|
bsa_radar
|
Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeover of user accounts if successfully exploited. Th…
|
CWE-862
Missing Authorization
|
CVE-2020-14944
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209516
|
5.4 |
MEDIUM
Network
|
globalradar
|
bsa_radar
|
The Firstname and Lastname parameters in Global RADAR BSA Radar 1.6.7234.24750 and earlier are vulnerable to stored cross-site scripting (XSS) via Update User Profile.
|
CWE-79
Cross-site Scripting
|
CVE-2020-14943
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209517
|
7.1 |
HIGH
Local
|
iobit
|
advanced_systemcare
|
IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Clean & Optimize feature with an NTFS junction and an Object Manager symbolic lin…
|
CWE-59
Link Following
|
CVE-2020-14990
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209518
|
9.8 |
CRITICAL
Network
|
chocolate-doom opensuse
|
crispy_doom chocolate_doom leap backports
|
The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading to a buffer overflow. A malicious user can overwrite the server's stack.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-14983
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209519
|
5.9 |
MEDIUM
Network
|
vipre
|
password_vault
|
The ThreatTrack VIPRE Password Vault app through 1.100.1090 for iOS has Missing SSL Certificate Validation.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-14981
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209520
|
5.9 |
MEDIUM
Network
|
sophos
|
sophos_secure_email
|
The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-14980
|
2024-11-21 14:04 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|