|
207871
|
7.5 |
HIGH
Network
|
os4ed
|
opensis
|
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.
|
CWE-287 CWE-640
Improper Authentication Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2020-27408
|
2024-11-21 14:21 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207872
|
3.3 |
LOW
Local
|
imagemagick redhat debian
|
imagemagick enterprise_linux debian_linux
|
In RestoreMSCWarning() of /coders/pdf.c there are several areas where calls to GetPixelIndex() could result in values outside the range of representable for the unsigned char type. The patch casts th…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-27771
|
2024-11-21 14:21 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207873
|
5.5 |
MEDIUM
Local
|
imagemagick debian
|
imagemagick debian_linux
|
Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in SubstituteString(), causing potential impact to application availability. This could be triggered …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-27770
|
2024-11-21 14:21 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207874
|
7.8 |
HIGH
Local
|
imagemagick debian
|
imagemagick debian_linux
|
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the r…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-27766
|
2024-11-21 14:21 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207875
|
3.3 |
LOW
Local
|
imagemagick redhat debian
|
imagemagick enterprise_linux debian_linux
|
A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero.…
|
CWE-369
Divide By Zero
|
CVE-2020-27765
|
2024-11-21 14:21 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207876
|
3.3 |
LOW
Local
|
imagemagick redhat debian
|
imagemagick enterprise_linux debian_linux
|
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the ran…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-27767
|
2024-11-21 14:21 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207877
|
6.8 |
MEDIUM
Local
|
canonical
|
snapcraft ubuntu_linux
|
In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both pl…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-27348
|
2024-11-21 14:21 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207878
|
6.1 |
MEDIUM
Network
|
lxml redhat debian fedoraproject netapp oracle
|
lxml enterprise_linux software_collections debian_linux fedora snapcenter communications_offline_mediation_controller zfs_storage_appliance_kit
|
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A r…
|
-
|
CVE-2020-27783
|
2024-11-21 14:21 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207879
|
7.5 |
HIGH
Network
|
freedesktop redhat debian
|
poppler enterprise_linux debian_linux
|
A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' …
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2020-27778
|
2024-11-21 14:21 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207880
|
3.3 |
LOW
Local
|
imagemagick debian
|
imagemagick debian_linux
|
In /MagickCore/statistic.c, there are several areas in ApplyEvaluateOperator() where a size_t cast should have been a ssize_t cast, which causes out-of-range values under some circumstances when a cr…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-27764
|
2024-11-21 14:21 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|