|
213281
|
9.1 |
CRITICAL
Network
|
libming
|
libming
|
Ming (aka libming) 0.4.8 has a heap-based buffer over-read (8 bytes) in the function decompileIF() in decompile.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-11894
|
2024-11-21 13:58 |
2020-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213282
|
6.1 |
MEDIUM
Network
|
svg2png_project
|
svg2png
|
svg2png 4.1.1 allows XSS with resultant SSRF via JavaScript inside an SVG document.
|
CWE-79
Cross-site Scripting
|
CVE-2020-11887
|
2024-11-21 13:58 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213283
|
8.1 |
HIGH
Network
|
opennms
|
horizon meridian
|
OpenNMS Horizon and Meridian allows HQL Injection in element/nodeList.htm (aka the NodeListController) via snmpParm or snmpParmValue to addCriteriaForSnmpParm. This affects Horizon before 25.2.1, Mer…
|
CWE-89
SQL Injection
|
CVE-2020-11886
|
2024-11-21 13:58 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213284
|
7.2 |
HIGH
Network
|
wso2
|
enterprise_integrator
|
WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintended network invocations such as SSRF via an uploade…
|
CWE-611 CWE-918
XXE Server-Side Request Forgery (SSRF)
|
CVE-2020-11885
|
2024-11-21 13:58 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213285
|
5.3 |
MEDIUM
Network
|
divante
|
storefront-api vue-storefront-api
|
In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpected HTTP requests lead to an exception that discloses the error stack trace, wit…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-11883
|
2024-11-21 13:58 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213286
|
6.5 |
MEDIUM
Network
|
kde
|
kmail
|
An issue was discovered in KDE KMail before 19.12.3. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make KMail attach local file…
|
NVD-CWE-Other
|
CVE-2020-11880
|
2024-11-21 13:58 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213287
|
6.5 |
MEDIUM
Network
|
gnome
|
evolution
|
An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach …
|
NVD-CWE-Other
|
CVE-2020-11879
|
2024-11-21 13:58 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213288
|
9.8 |
CRITICAL
Network
|
jitsi
|
meet
|
The Jitsi Meet (aka docker-jitsi-meet) stack on Docker before stable-4384-1 uses default passwords (such as passw0rd) for system accounts.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-11878
|
2024-11-21 13:58 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213289
|
7.5 |
HIGH
Network
|
zoom
|
meetings
|
airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption. NOTE: the vendor states that this IV is used only within unreachable…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-11877
|
2024-11-21 13:58 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213290
|
7.5 |
HIGH
Network
|
zoom
|
meetings
|
airhost.exe in Zoom Client for Meetings 4.6.11 uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of an OpenSSL EVP AES-256 CBC context. NOTE: the vendor states that this initializa…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-11876
|
2024-11-21 13:58 |
2020-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|