|
208401
|
8.6 |
HIGH
Network
|
spice-space
|
spice-server
|
An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can restart KVMvirtual machine without any authorization.…
|
CWE-862
Missing Authorization
|
CVE-2020-23793
|
2024-11-21 14:14 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208402
|
7.8 |
HIGH
Local
|
rockcarry
|
ffjpeg
|
Buffer Overflow vulnerability in jfif_decode() function in rockcarry ffjpeg through version 1.0.0, allows local attackers to execute arbitrary code due to an issue with ALIGN.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-24222
|
2024-11-21 14:14 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208403
|
5.5 |
MEDIUM
Local
|
jerryscript
|
jerryscript
|
An issue was discovered in ecma-helpers.c in jerryscript version 2.3.0, allows local attackers to cause a denial of service (DoS) (Null Pointer Dereference).
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-24187
|
2024-11-21 14:14 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208404
|
6.1 |
MEDIUM
Network
|
laborator
|
kalium
|
Cross Site Scripting (XSS) vulnerability in Name Input Field in Contact Us form in Laborator Kalium before 3.0.4, allows remote attackers to execute arbitrary code.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24075
|
2024-11-21 14:14 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208405
|
6.5 |
MEDIUM
Network
|
swoole
|
swoole
|
A HTTP response header injection vulnerability in Swoole v4.5.2 allows attackers to execute arbitrary code via supplying a crafted URL.
|
CWE-74
Injection
|
CVE-2020-24275
|
2024-11-21 14:14 |
2023-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208406
|
5.5 |
MEDIUM
Local
|
asn1c_project
|
asn1c
|
An issue was discovered in asn1c through v0.9.28. A NULL pointer dereference exists in the function _default_error_logger() located in asn1fix.c. It allows an attacker to cause Denial of Service.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-23911
|
2024-11-21 14:14 |
2023-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208407
|
5.5 |
MEDIUM
Local
|
asn1c_project
|
asn1c
|
Stack-based buffer overflow vulnerability in asn1c through v0.9.28 via function genhash_get in genhash.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-23910
|
2024-11-21 14:14 |
2023-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208408
|
7.1 |
HIGH
Local
|
advancemame
|
advancemame
|
Heap-based buffer over-read in function png_convert_4 in file pngex.cc in AdvanceMAME through 2.1.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-23909
|
2024-11-21 14:14 |
2023-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208409
|
9.8 |
CRITICAL
Network
|
victor_cms_project
|
victor_cms
|
SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request.
|
CWE-89
SQL Injection
|
CVE-2020-23966
|
2024-11-21 14:14 |
2023-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208410
|
7.8 |
HIGH
Local
|
mremoteng
|
mremoteng
|
An issue in mRemoteNG v1.76.20 allows attackers to escalate privileges via a crafted executable file. NOTE: third parties were unable to reproduce any scenario in which the claimed access of BUILTIN\…
|
CWE-269
Improper Privilege Management
|
CVE-2020-24307
|
2024-11-21 14:14 |
2023-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|