|
210621
|
4.9 |
MEDIUM
Network
|
ntp opensuse netapp oracle
|
ntp leap cloud_backup steelstore_cloud_integrated_storage 8300_firmware 8700_firmware a400_firmware h410c_firmware h300s_firmware h500s_firmware h700s_firmware h300e_…
|
ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations wher…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-15025
|
2024-11-21 14:04 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210622
|
6.1 |
MEDIUM
Network
|
gleamtech
|
fileultimate
|
The FileExplorer component in GleamTech FileUltimate 6.1.5.0 allows XSS via an SVG document.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15015
|
2024-11-21 14:04 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210623
|
6.5 |
MEDIUM
Network
|
playsms
|
playsms
|
playSMS through 1.4.3 is vulnerable to session fixation.
|
CWE-384
Session Fixation
|
CVE-2020-15018
|
2024-11-21 14:04 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210624
|
8.8 |
HIGH
Network
|
pramod
|
blogcms
|
pramodmahato BlogCMS through 2019-12-31 has admin/changepass.php CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-15014
|
2024-11-21 14:04 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210625
|
4.3 |
MEDIUM
Network
|
gnu canonical debian
|
mailman ubuntu_linux debian_linux
|
GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.
|
CWE-74
Injection
|
CVE-2020-15011
|
2024-11-21 14:04 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210626
|
9.8 |
CRITICAL
Network
|
idsoftware doom_vanille_project
|
tech_1 doom_vanille
|
A buffer overflow in the M_LoadDefaults function in m_misc.c in id Tech 1 (aka Doom engine) allows arbitrary code execution via an unsafe usage of fscanf, because it does not limit the number of char…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-15007
|
2024-11-21 14:04 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210627
|
5.4 |
MEDIUM
Network
|
bludit
|
bludit
|
Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15006
|
2024-11-21 14:04 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210628
|
8.1 |
HIGH
Network
|
f-secure
|
safe
|
An issue was discovered in F-Secure SAFE 17.7 on macOS. Due to incorrect client version verification, an attacker can connect to a privileged XPC service, and execute privileged commands on the syste…
|
NVD-CWE-noinfo
|
CVE-2020-14978
|
2024-11-21 14:04 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210629
|
8.1 |
HIGH
Network
|
f-secure
|
safe
|
An issue was discovered in F-Secure SAFE 17.7 on macOS. The XPC services use the PID to identify the connecting client, which allows an attacker to perform a PID reuse attack and connect to a privile…
|
NVD-CWE-noinfo
|
CVE-2020-14977
|
2024-11-21 14:04 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210630
|
5.5 |
MEDIUM
Local
|
gns3
|
ubridge
|
GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2.1.17, allows a local attacker to read arbitrary files because it handles configuration-file errors by printing the configuration …
|
CWE-269
Improper Privilege Management
|
CVE-2020-14976
|
2024-11-21 14:04 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|