|
208961
|
7.5 |
HIGH
Network
|
axiosys
|
bento4
|
A heap-based buffer overflow exists in the AP4_StdcFileByteStream::ReadPartial component located in /StdC/Ap4StdCFileByteStream.cpp of Bento4 version 06c39d9. This issue can lead to a denial of servi…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-23332
|
2024-11-21 14:13 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208962
|
7.5 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_DescriptorListWriter::Action component located in /Core/Ap4Descriptor.h. It allows an attacker to cause…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-23331
|
2024-11-21 14:13 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208963
|
7.5 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_Stz2Atom::GetSampleSize component located in /Core/Ap4Stz2Atom.cpp. It allows an attacker to cause a de…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-23330
|
2024-11-21 14:13 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208964
|
9.8 |
CRITICAL
Network
|
phome
|
empirecms
|
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.
|
CWE-94
Code Injection
|
CVE-2020-22937
|
2024-11-21 14:13 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208965
|
8.8 |
HIGH
Network
|
express-cart_project
|
express-cart
|
Cross Site Request Forgery (CSRF) vulnerability in Express cart v1.1.16 allows attackers to add an administrator account, add discount code or other unspecified impacts.
|
CWE-352
Origin Validation Error
|
CVE-2020-22403
|
2024-11-21 14:13 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208966
|
5.5 |
MEDIUM
Local
|
kuba_project
|
kuba
|
A vulnerability in all versions of Kuba allows attackers to overwrite arbitrary files in arbitrary directories with crafted Zip files due to improper validation of file paths in .zip archives.
|
CWE-22
Path Traversal
|
CVE-2020-23172
|
2024-11-21 14:13 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208967
|
5.5 |
MEDIUM
Local
|
nim-lang
|
nim-lang
|
A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via a crafted zip file with dot-slash characters included in the name of the craft…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2020-23171
|
2024-11-21 14:13 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208968
|
9.8 |
CRITICAL
Network
|
rconfig
|
rconfig
|
rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed directly to the exec function without being escaped.
|
CWE-78
OS Command
|
CVE-2020-23151
|
2024-11-21 14:13 |
2021-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208969
|
7.5 |
HIGH
Network
|
rconfig
|
rconfig
|
A SQL injection vulnerability in config.inc.php of rConfig 3.9.5 allows attackers to access sensitive database information via a crafted GET request to install/lib/ajaxHandlers/ajaxDbInstall.php.
|
CWE-89
SQL Injection
|
CVE-2020-23150
|
2024-11-21 14:13 |
2021-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208970
|
7.5 |
HIGH
Network
|
rconfig
|
rconfig
|
The dbName parameter in ajaxDbInstall.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a SQL injection and access sensitive database information.
|
CWE-89
SQL Injection
|
CVE-2020-23149
|
2024-11-21 14:13 |
2021-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|