|
209131
|
9.8 |
CRITICAL
Network
|
online_shopping_alphaware_project
|
online_shopping_alphaware
|
A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to bypass the authentication process via email and password parameters.
|
CWE-89
SQL Injection
|
CVE-2020-24208
|
2024-11-21 14:14 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209132
|
9.8 |
CRITICAL
Network
|
snmptt debian
|
snmptt debian_linux
|
SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.
|
CWE-273
Improper Check for Dropped Privileges
|
CVE-2020-24361
|
2024-11-21 14:14 |
2020-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209133
|
5.5 |
MEDIUM
Local
|
f5
|
njs
|
njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor considers the issue to be "fluff" in the NGINX use case because there is no remote …
|
CWE-416
Use After Free
|
CVE-2020-24349
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209134
|
5.5 |
MEDIUM
Local
|
f5
|
njs
|
njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-24348
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209135
|
5.5 |
MEDIUM
Local
|
f5
|
njs
|
njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_lvlhsh_level_find in njs_lvlhsh.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-24347
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209136
|
7.8 |
HIGH
Local
|
f5
|
njs
|
njs through 0.4.3, used in NGINX, has a use-after-free in njs_json_parse_iterator_call in njs_json.c.
|
CWE-416
Use After Free
|
CVE-2020-24346
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209137
|
7.8 |
HIGH
Local
|
jerryscript
|
jerryscript
|
JerryScript through 2.3.0 allows stack consumption via function a(){new new Proxy(a,{})}JSON.parse("[]",a). NOTE: the vendor states that the problem is the lack of the --stack-limit option
|
CWE-787
Out-of-bounds Write
|
CVE-2020-24345
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209138
|
7.1 |
HIGH
Local
|
jerryscript
|
jerryscript
|
JerryScript through 2.3.0 has a (function({a=arguments}){const arguments}) buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-24344
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209139
|
7.8 |
HIGH
Local
|
artifex
|
mujs
|
Artifex MuJS through 1.0.7 has a use-after-free in jsrun.c because of unconditional marking in jsgc.c.
|
CWE-416
Use After Free
|
CVE-2020-24343
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209140
|
7.8 |
HIGH
Local
|
lua fedoraproject
|
lua fedora
|
Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-24342
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|