|
212521
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an o…
|
CWE-346
Origin Validation Error
|
CVE-2020-15682
|
2024-11-21 14:06 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212522
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
When multiple WASM threads had a reference to a module, and were looking up exported functions, one WASM thread could have overwritten another's entry in a shared stub table, resulting in a potential…
|
NVD-CWE-noinfo
|
CVE-2020-15681
|
2024-11-21 14:06 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212523
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguished from a broken image size of a non-existent protocol handler. This allowed a…
|
NVD-CWE-noinfo
|
CVE-2020-15680
|
2024-11-21 14:06 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212524
|
9.8 |
CRITICAL
Network
|
tiki
|
tiki
|
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-15906
|
2024-11-21 14:06 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212525
|
7.5 |
HIGH
Network
|
netwrix
|
account_lockout_examiner
|
Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator (that is configured within the product in it…
|
CWE-200
Information Exposure
|
CVE-2020-15931
|
2024-11-21 14:06 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212526
|
7.3 |
HIGH
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-15822
|
2024-11-21 14:06 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212527
|
7.5 |
HIGH
Network
|
gopro
|
gpmf-parser
|
GoPro gpmf-parser 1.5 has a division-by-zero vulnerability in GPMF_ScaledData(). Parsing malicious input can result in a crash.
|
CWE-369
Divide By Zero
|
CVE-2020-16161
|
2024-11-21 14:06 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212528
|
7.5 |
HIGH
Network
|
gopro
|
gpmf-parser
|
GoPro gpmf-parser 1.5 has a division-by-zero vulnerability in GPMF_Decompress(). Parsing malicious input can result in a crash.
|
CWE-369
Divide By Zero
|
CVE-2020-16160
|
2024-11-21 14:06 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212529
|
9.1 |
CRITICAL
Network
|
gopro
|
gpmf-parser
|
GoPro gpmf-parser 1.5 has a heap out-of-bounds read and segfault in GPMF_ScaledData(). Parsing malicious input can result in a crash or information disclosure.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-16159
|
2024-11-21 14:06 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212530
|
8.8 |
HIGH
Network
|
gopro
|
gpmf-parser
|
GoPro gpmf-parser through 1.5 has a stack out-of-bounds write vulnerability in GPMF_ExpandComplexTYPE(). Parsing malicious input can result in a crash or potentially arbitrary code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-16158
|
2024-11-21 14:06 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|