|
210711
|
9.8 |
CRITICAL
Network
|
wavlink
|
wl-wn530hg4_firmware
|
An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulnerabilities exist in CGI scripts, leading to remote code execution with root pri…
|
CWE-78
OS Command
|
CVE-2020-15489
|
2024-11-21 14:05 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210712
|
7.5 |
HIGH
Network
|
journal-theme
|
journal
|
The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-15478
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210713
|
7.5 |
HIGH
Network
|
ntop debian
|
ndpi debian_linux
|
In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-15476
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210714
|
9.8 |
CRITICAL
Network
|
ntop
|
ndpi
|
In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.
|
CWE-416
Use After Free
|
CVE-2020-15475
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210715
|
9.8 |
CRITICAL
Network
|
ntop
|
ndpi
|
In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-15474
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210716
|
9.1 |
CRITICAL
Network
|
ntop
|
ndpi
|
In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-15473
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210717
|
9.1 |
CRITICAL
Network
|
ntop debian
|
ndpi debian_linux
|
In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-15472
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210718
|
9.1 |
CRITICAL
Network
|
ntop
|
ndpi
|
In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-15471
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210719
|
5.5 |
MEDIUM
Local
|
rockcarry
|
ffjpeg
|
ffjpeg through 2020-02-24 has a heap-based buffer overflow in jfif_decode in jfif.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-15470
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210720
|
9.8 |
CRITICAL
Network
|
persian_vip_download_script_project
|
persian_vip_download_script
|
Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter.
|
CWE-89
SQL Injection
|
CVE-2020-15468
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|