|
208901
|
6.5 |
MEDIUM
Network
|
libav
|
libav
|
In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_b_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-18775
|
2024-11-21 14:08 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208902
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.
|
CWE-369
Divide By Zero
|
CVE-2020-18774
|
2024-11-21 14:08 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208903
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-18773
|
2024-11-21 14:08 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208904
|
8.1 |
HIGH
Network
|
exiv2 debian
|
exiv2 debian_linux
|
Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-18771
|
2024-11-21 14:08 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208905
|
7.5 |
HIGH
Network
|
eclipse
|
cyclone_data_distribution_service
|
A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-18735
|
2024-11-21 14:08 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208906
|
7.5 |
HIGH
Network
|
eclipse
|
cyclone_data_distribution_service
|
A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-18734
|
2024-11-21 14:08 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208907
|
7.5 |
HIGH
Network
|
iec104_project
|
iec104
|
A segmentation violation in the Iec104_Deal_FirmUpdate function of IEC104 v1.0 allows attackers to cause a denial of service (DOS).
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-18731
|
2024-11-21 14:08 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208908
|
7.5 |
HIGH
Network
|
iec104_project
|
iec104
|
A segmentation violation in the Iec104_Deal_I function of IEC104 v1.0 allows attackers to cause a denial of service (DOS).
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-18730
|
2024-11-21 14:08 |
2021-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208909
|
7.2 |
HIGH
Network
|
phpmywind
|
phpmywind
|
Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-18886
|
2024-11-21 14:08 |
2021-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208910
|
7.2 |
HIGH
Network
|
phpmywind
|
phpmywind
|
Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'.
|
CWE-77
Command Injection
|
CVE-2020-18885
|
2024-11-21 14:08 |
2021-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|