|
210501
|
9.8 |
CRITICAL
Network
|
vaethink
|
vaethink
|
An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a webshell via changing uploaded file suffixes to ".php".
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19302
|
2024-11-21 14:09 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210502
|
9.8 |
CRITICAL
Network
|
vaethink
|
vaethink
|
A vulnerability in the vae_admin_rule database table of vaeThink v1.0.1 allows attackers to execute arbitrary code via a crafted payload in the condition parameter.
|
CWE-863
Incorrect Authorization
|
CVE-2020-19301
|
2024-11-21 14:09 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210503
|
8.8 |
HIGH
Network
|
struktur
|
libheif
|
An issue was discovered in heif::Box_iref::get_references in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impact due to an invalid memory read.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-19499
|
2024-11-21 14:09 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210504
|
8.8 |
HIGH
Network
|
struktur
|
libheif
|
Floating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impacts.
|
NVD-CWE-noinfo
|
CVE-2020-19498
|
2024-11-21 14:09 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210505
|
8.8 |
HIGH
Network
|
matio_project
|
matio
|
Integer overflow vulnerability in Mat_VarReadNextInfo5 in mat5.c in tbeu matio (aka MAT File I/O Library) 1.5.17, allows attackers to cause a Denial of Service or possibly other unspecified impacts.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-19497
|
2024-11-21 14:09 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210506
|
7.8 |
HIGH
Local
|
sam2p_project
|
sam2p
|
There is a floating point exception in ReadImage that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.
|
NVD-CWE-noinfo
|
CVE-2020-19492
|
2024-11-21 14:09 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210507
|
7.8 |
HIGH
Local
|
sam2p_project
|
sam2p
|
There is an invalid memory access bug in cgif.c that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-19491
|
2024-11-21 14:09 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210508
|
5.5 |
MEDIUM
Local
|
tinyexr_project
|
tinyexr
|
tinyexr 0.9.5 has a integer overflow over-write in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-19490
|
2024-11-21 14:09 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210509
|
5.5 |
MEDIUM
Local
|
gpac
|
gpac
|
An issue was discovered in box_code_apple.c:119 in Gpac MP4Box 0.8.0, allows attackers to cause a Denial of Service due to an invalid read on function ilst_item_Read.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-19488
|
2024-11-21 14:09 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210510
|
5.5 |
MEDIUM
Local
|
gpac
|
gpac
|
An issue was discovered in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid memory read in gf_m2ts_process_pmt in media_tools/mpegts.c that can cause a denial of service via a cra…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-19481
|
2024-11-21 14:09 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|