|
211001
|
9.1 |
CRITICAL
Network
|
ntop debian
|
ndpi debian_linux
|
In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-15472
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211002
|
9.1 |
CRITICAL
Network
|
ntop
|
ndpi
|
In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-15471
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211003
|
5.5 |
MEDIUM
Local
|
rockcarry
|
ffjpeg
|
ffjpeg through 2020-02-24 has a heap-based buffer overflow in jfif_decode in jfif.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-15470
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211004
|
9.8 |
CRITICAL
Network
|
persian_vip_download_script_project
|
persian_vip_download_script
|
Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter.
|
CWE-89
SQL Injection
|
CVE-2020-15468
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211005
|
6.1 |
MEDIUM
Network
|
nozominetworks
|
guardian
|
Nozomi Guardian before 19.0.4 allows attackers to achieve stored XSS (in the web front end) by leveraging the ability to create a custom field with a crafted field name.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15307
|
2024-11-21 14:05 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211006
|
9.8 |
CRITICAL
Network
|
draytek
|
vigor3900_firmware vigor2960_firmware vigor300b_firmware
|
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-pytho…
|
CWE-78
OS Command
|
CVE-2020-15415
|
2024-11-21 14:05 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211007
|
4.3 |
MEDIUM
Network
|
misp
|
misp
|
An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding to allow a user to send an event contact form.
|
CWE-862
Missing Authorization
|
CVE-2020-15412
|
2024-11-21 14:05 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211008
|
9.8 |
CRITICAL
Network
|
misp
|
misp
|
An issue was discovered in MISP 2.4.128. app/Controller/AttributesController.php has insufficient ACL checks in the attachment downloader.
|
NVD-CWE-noinfo
|
CVE-2020-15411
|
2024-11-21 14:05 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211009
|
4.4 |
MEDIUM
Local
|
iobit
|
malware_fighter
|
IOBit Malware Fighter Pro 8.0.2.547 allows local users to gain privileges for file deletion by manipulating malicious flagged file locations with an NTFS junction and an Object Manager symbolic link.
|
CWE-59
Link Following
|
CVE-2020-15401
|
2024-11-21 14:05 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211010
|
4.3 |
MEDIUM
Network
|
cakefoundation
|
cakephp
|
CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2020-15400
|
2024-11-21 14:05 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|