|
208481
|
8.8 |
HIGH
Network
|
dlink
|
dsr-150_firmware dsr-150n_firmware dsr-250_firmware dsr-250n_firmware dsr-500_firmware dsr-500n_firmware dsr-500ac_firmware dsr-1000_firmware dsr-1000n_firmware dsr-1000ac_…
|
An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to …
|
CWE-20 CWE-78
Improper Input Validation OS Command
|
CVE-2020-25759
|
2024-11-21 14:18 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208482
|
8.8 |
HIGH
Network
|
dlink
|
dsr-150_firmware dsr-150n_firmware dsr-250_firmware dsr-250n_firmware dsr-500_firmware dsr-500n_firmware dsr-500ac_firmware dsr-1000_firmware dsr-1000n_firmware dsr-1000ac_…
|
An issue was discovered on D-Link DSR-250 3.17 devices. Insufficient validation of configuration file checksums could allow a remote, authenticated attacker to inject arbitrary crontab entries into s…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-25758
|
2024-11-21 14:18 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208483
|
8.8 |
HIGH
Adjacent
|
dlink
|
dsr-150_firmware dsr-150n_firmware dsr-250_firmware dsr-250n_firmware dsr-500_firmware dsr-500n_firmware dsr-500ac_firmware dsr-1000_firmware dsr-1000n_firmware dsr-1000ac_…
|
A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with r…
|
CWE-20 CWE-78
Improper Input Validation OS Command
|
CVE-2020-25757
|
2024-11-21 14:18 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208484
|
7.8 |
HIGH
Local
|
x.org redhat
|
x_server enterprise_linux
|
A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data …
|
-
|
CVE-2020-25712
|
2024-11-21 14:18 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208485
|
6.5 |
MEDIUM
Network
|
microfocus
|
filr
|
Unauthorized disclosure of sensitive information vulnerability in Micro Focus Filr product. Affecting all 3.x and 4.x versions. The vulnerability could be exploited to disclose unauthorized sensitive…
|
NVD-CWE-noinfo
|
CVE-2020-25838
|
2024-11-21 14:18 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208486
|
8.8 |
HIGH
Network
|
totolink
|
a3002r_firmware a3002ru-v1_firmware a3002ru-v2_firmware a702r-v2_firmware a702r-v3_firmware n100re-v3_firmware n150rt_firmware n200re-v3_firmware n200re-v4_firmware n210re_…
|
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.
|
CWE-78 CWE-862
OS Command Missing Authorization
|
CVE-2020-25499
|
2024-11-21 14:18 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208487
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.
|
-
|
CVE-2020-25627
|
2024-11-21 14:18 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208488
|
5.5 |
MEDIUM
Local
|
imagemagick debian
|
imagemagick debian_linux
|
In CatromWeights(), MeshInterpolate(), InterpolatePixelChannel(), InterpolatePixelChannels(), and InterpolatePixelInfo(), which are all functions in /MagickCore/pixel.c, there were multiple unconstra…
|
-
|
CVE-2020-25676
|
2024-11-21 14:18 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208489
|
3.3 |
LOW
Local
|
imagemagick debian
|
imagemagick debian_linux
|
In the CropImage() and CropImageToTiles() routines of MagickCore/transform.c, rounding calculations performed on unconstrained pixel offsets was causing undefined behavior in the form of integer over…
|
-
|
CVE-2020-25675
|
2024-11-21 14:18 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208490
|
5.5 |
MEDIUM
Local
|
imagemagick debian
|
imagemagick debian_linux
|
WriteOnePNGImage() from coders/png.c (the PNG coder) has a for loop with an improper exit condition that can allow an out-of-bounds READ via heap-buffer-overflow. This occurs because it is possible f…
|
-
|
CVE-2020-25674
|
2024-11-21 14:18 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|