|
209431
|
8.8 |
HIGH
Network
|
newsone_cms_project
|
newsone_cms
|
An arbitrary file upload in the <input type="file" name="user_image"> component of NewsOne CMS v1.1.0 allows attackers to webshell and execute arbitrary commands.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21976
|
2024-11-21 14:12 |
2021-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209432
|
5.4 |
MEDIUM
Network
|
eyoucms
|
eyoucms
|
A stored cross site scripting (XSS) vulnerability in the web_attr_2 field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21930
|
2024-11-21 14:12 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209433
|
5.4 |
MEDIUM
Network
|
eyoucms
|
eyoucms
|
A stored cross site scripting (XSS) vulnerability in the web_copyright field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21929
|
2024-11-21 14:12 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209434
|
6.5 |
MEDIUM
Network
|
ffmpeg debian
|
ffmpeg debian_linux
|
A heap-use-after-free in the mpeg_mux_write_packet function in libavformat/mpegenc.c of FFmpeg 4.2 allows to cause a denial of service (DOS) via a crafted avi file.
|
CWE-416
Use After Free
|
CVE-2020-21697
|
2024-11-21 14:12 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209435
|
8.8 |
HIGH
Network
|
ffmpeg debian
|
ffmpeg debian_linux
|
A heap-use-after-free in the av_freep function in libavutil/mem.c of FFmpeg 4.2 allows attackers to execute arbitrary code.
|
CWE-416
Use After Free
|
CVE-2020-21688
|
2024-11-21 14:12 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209436
|
5.5 |
MEDIUM
Local
|
fig2dev_project
|
fig2dev
|
A global buffer overflow in the put_font in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-21684
|
2024-11-21 14:12 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209437
|
5.5 |
MEDIUM
Local
|
fig2dev_project
|
fig2dev
|
A global buffer overflow in the shade_or_tint_name_after_declare_color in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-21683
|
2024-11-21 14:12 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209438
|
5.5 |
MEDIUM
Local
|
fig2dev_project
|
fig2dev
|
A global buffer overflow in the set_fill component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ge format.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-21682
|
2024-11-21 14:12 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209439
|
5.5 |
MEDIUM
Local
|
fig2dev_project
|
fig2dev
|
A global buffer overflow in the set_color component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ge format.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-21681
|
2024-11-21 14:12 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209440
|
5.5 |
MEDIUM
Local
|
fig2dev_project
|
fig2dev
|
A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21680
|
2024-11-21 14:12 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|