|
210471
|
6.4 |
MEDIUM
Local
|
gnu redhat canonical debian suse microsoft opensuse
|
grub2 enterprise_linux ubuntu_linux debian_linux suse_linux_enterprise_server enterprise_linux_atomic_host openshift_container_platform windows_server_2012 windows_10 windo…
|
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executin…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2020-15706
|
2024-11-21 14:06 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210472
|
6.4 |
MEDIUM
Local
|
gnu redhat canonical debian suse opensuse microsoft
|
grub2 enterprise_linux ubuntu_linux debian_linux suse_linux_enterprise_server enterprise_linux_atomic_host leap openshift_container_platform windows_server_2012 windows_10<…
|
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported direc…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-15705
|
2024-11-21 14:06 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210473
|
6.1 |
MEDIUM
Network
|
kitodo
|
kitodo.presentation
|
The dlf (aka Kitodo.Presentation) extension before 3.1.2 for TYPO3 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-16095
|
2024-11-21 14:06 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210474
|
7.5 |
HIGH
Network
|
claws-mail fedoraproject
|
claws-mail fedora
|
In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.
|
CWE-674
Uncontrolled Recursion
|
CVE-2020-16094
|
2024-11-21 14:06 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210475
|
7.5 |
HIGH
Network
|
grin
|
grin
|
Grin 3.0.0 before 4.0.0 has insufficient validation of data related to Mimblewimble.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-15899
|
2024-11-21 14:06 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210476
|
9.8 |
CRITICAL
Network
|
artifex canonical opensuse
|
ghostscript ubuntu_linux leap
|
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'po…
|
CWE-787 CWE-191
Out-of-bounds Write Integer Underflow (Wrap or Wraparound)
|
CVE-2020-15900
|
2024-11-21 14:06 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210477
|
5.3 |
MEDIUM
Local
|
qemu debian canonical
|
qemu debian_linux ubuntu_linux
|
hw/net/xgmac.c in the XGMAC Ethernet controller in QEMU before 07-20-2020 has a buffer overflow. This occurs during packet transmission and affects the highbank and midway emulated machines. A guest …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-15863
|
2024-11-21 14:06 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210478
|
9.9 |
CRITICAL
Network
|
rconfig
|
rconfig
|
rConfig 3.9.5 could allow a remote authenticated attacker to execute arbitrary code on the system, because of an error in the search.crud.php script. An attacker could exploit this vulnerability usin…
|
NVD-CWE-noinfo
|
CVE-2020-15715
|
2024-11-21 14:06 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210479
|
8.8 |
HIGH
Network
|
rconfig
|
rconfig
|
rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.crud.php script using the custom_Location parameter, which could allow t…
|
CWE-89
SQL Injection
|
CVE-2020-15714
|
2024-11-21 14:06 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210480
|
8.8 |
HIGH
Network
|
rconfig
|
rconfig
|
rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.php script using the sortBy parameter, which could allow the attacker to…
|
CWE-89
SQL Injection
|
CVE-2020-15713
|
2024-11-21 14:06 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|