|
209531
|
8.8 |
HIGH
Network
|
gnu
|
libredwg
|
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:48.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21818
|
2024-11-21 14:12 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209532
|
6.5 |
MEDIUM
Network
|
gnu
|
libredwg
|
A null pointer dereference issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:29. which causes a denial of service (application crash).
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-21817
|
2024-11-21 14:12 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209533
|
8.8 |
HIGH
Network
|
gnu
|
libredwg
|
A heab based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:46.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21816
|
2024-11-21 14:12 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209534
|
6.5 |
MEDIUM
Network
|
gnu
|
libredwg
|
A null pointer deference issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114, which causes a denial of service (application crash).
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-21815
|
2024-11-21 14:12 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209535
|
8.8 |
HIGH
Network
|
gnu
|
libredwg
|
A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlwescape ../../programs/escape.c:97.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21814
|
2024-11-21 14:12 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209536
|
7.8 |
HIGH
Local
|
gnu
|
libredwg
|
A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21813
|
2024-11-21 14:12 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209537
|
7.5 |
HIGH
Network
|
zzcms
|
zzcms
|
Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-21342
|
2024-11-21 14:12 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209538
|
8.8 |
HIGH
Network
|
iwt
|
facesentry_access_control_system_firmware
|
iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell …
|
CWE-78
OS Command
|
CVE-2020-21999
|
2024-11-21 14:12 |
2021-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209539
|
9.8 |
CRITICAL
Network
|
uniview
|
isc2500-s_firmware
|
An issue was discovered in uniview ISC2500-S. This is an upload vulnerability where an attacker can upload malicious code via /Interface/DevManage/EC.php?cmd=upload
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21452
|
2024-11-21 14:12 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209540
|
5.4 |
MEDIUM
Network
|
screenly
|
screenly
|
Cross Site Scriptiong vulnerabilityin Screenly screenly-ose all versions, including v1.8.2 (2019-09-25-Screenly-OSE-lite.img), in the 'Add Asset' page via manipulation of a 'URL' field, which could l…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21101
|
2024-11-21 14:12 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|