|
208061
|
7.5 |
HIGH
Network
|
moddable
|
moddable
|
Null Pointer Dereference. in xObjectBindingFromExpression at moddable/xs/sources/xsSyntaxical.c:3419 in Moddable SDK before OS200908 causes a denial of service (SEGV).
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-25465
|
2024-11-21 14:18 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208062
|
7.5 |
HIGH
Network
|
moddable
|
moddable
|
Heap buffer overflow at moddable/xs/sources/xsDebug.c in Moddable SDK before before 20200903. The top stack frame is only partially initialized because the stack overflowed while creating the frame. …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-25464
|
2024-11-21 14:18 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208063
|
7.5 |
HIGH
Network
|
moddable
|
moddable
|
Invalid Memory Access in fxUTF8Decode at moddable/xs/sources/xsCommon.c:916 in Moddable SDK before OS200908 causes a denial of service (SEGV).
|
NVD-CWE-Other
|
CVE-2020-25463
|
2024-11-21 14:18 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208064
|
6.5 |
MEDIUM
Network
|
infinispan redhat netapp
|
infinispan data_grid active_iq_unified_manager
|
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can…
|
CWE-862
Missing Authorization
|
CVE-2020-25711
|
2024-11-21 14:18 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208065
|
8.1 |
HIGH
Network
|
cimg fedoraproject
|
cimg fedora
|
A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overflows in load_pnm() can be triggered by a specially crafted input file processed by CImg, which can l…
|
-
|
CVE-2020-25693
|
2024-11-21 14:18 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208066
|
7.5 |
HIGH
Network
|
fasterxml netapp fedoraproject quarkus apache oracle
|
jackson-databind oncommand_workflow_automation service_level_manager oncommand_api_services fedora quarkus iotdb webcenter_portal banking_platform utilities_framework ag…
|
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from t…
|
CWE-611
XXE
|
CVE-2020-25649
|
2024-11-21 14:18 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208067
|
7.4 |
HIGH
Network
|
hibernate debian quarkus oracle
|
hibernate_orm debian_linux quarkus retail_customer_management_and_segmentation_foundation communications_cloud_native_core_console
|
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is use…
|
-
|
CVE-2020-25638
|
2024-11-21 14:18 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208068
|
3.2 |
LOW
Local
|
qemu debian
|
qemu debian_linux
|
A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged us…
|
-
|
CVE-2020-25723
|
2024-11-21 14:18 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208069
|
5.5 |
MEDIUM
Local
|
linux debian starwindsoftware
|
linux_kernel debian_linux starwind_san_\&_nas command_center starwind_virtual_san starwind_hyperconverged_appliance
|
A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER. A local user could use this flaw to starve the resources causing denia…
|
-
|
CVE-2020-25704
|
2024-11-21 14:18 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208070
|
4.1 |
MEDIUM
Local
|
linux redhat debian starwindsoftware
|
linux_kernel enterprise_linux debian_linux starwind_virtual_san
|
A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access …
|
-
|
CVE-2020-25656
|
2024-11-21 14:18 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|