|
208491
|
5.5 |
MEDIUM
Local
|
rockcarry
|
ffjpeg
|
A heap based buffer overflow vulnerability exists in ffjpeg through 2020-07-02 in the jfif_decode(void *ctxt, BMP *pb) function at ffjpeg/src/jfif.c (line 544 & line 545), which could cause a denial …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-23852
|
2024-11-21 14:14 |
2021-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208492
|
5.5 |
MEDIUM
Local
|
rockcarry
|
ffjpeg
|
A stack-based buffer overflow vulnerability exists in ffjpeg through 2020-07-02 in the jfif_decode(void *ctxt, BMP *pb) function at ffjpeg/src/jfif.c:513:28, which could cause a denial of service by …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-23851
|
2024-11-21 14:14 |
2021-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208493
|
7.1 |
HIGH
Local
|
upx_project fedoraproject
|
upx fedora
|
A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-24119
|
2024-11-21 14:14 |
2021-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208494
|
9.8 |
CRITICAL
Network
|
yfcmf
|
yfcmf
|
YFCMF v2.3.1 has a Remote Command Execution (RCE) vulnerability in the index.php.
|
NVD-CWE-noinfo
|
CVE-2020-23691
|
2024-11-21 14:14 |
2021-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208495
|
4.8 |
MEDIUM
Network
|
yfcmf
|
yfcmf
|
In YFCMF v2.3.1, there is a stored XSS vulnerability in the comments section of the news page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23689
|
2024-11-21 14:14 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208496
|
8.8 |
HIGH
Network
|
ilias
|
ilias
|
A local file inclusion vulnerability in ILIAS before 5.3.19, 5.4.10 and 6.0 allows remote authenticated attackers to execute arbitrary code via the import of personal data.
|
NVD-CWE-Other
|
CVE-2020-23996
|
2024-11-21 14:14 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208497
|
6.5 |
MEDIUM
Network
|
ilias
|
ilias
|
An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-23995
|
2024-11-21 14:14 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208498
|
9.8 |
CRITICAL
Network
|
uxper
|
golo
|
An Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-23790
|
2024-11-21 14:14 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208499
|
5.5 |
MEDIUM
Local
|
gpac
|
gpac
|
An issue was discovered in gpac before 1.0.1. A NULL pointer dereference exists in the function dump_isom_sdp located in filedump.c. It allows an attacker to cause Denial of Service.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-23932
|
2024-11-21 14:14 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208500
|
7.1 |
HIGH
Local
|
gpac
|
gpac
|
An issue was discovered in gpac before 1.0.1. The abst_box_read function in box_code_adobe.c has a heap-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-23931
|
2024-11-21 14:14 |
2021-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|