|
208551
|
8.1 |
HIGH
Network
|
fasterxml oracle debian
|
jackson-databind application_testing_suite agile_plm communications_policy_management communications_diameter_signaling_router communications_offline_mediation_controller communicat…
|
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-24750
|
2024-11-21 14:16 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208552
|
9.8 |
CRITICAL
Network
|
objective_open_cbor_run-time_project
|
objective_open_cbor_run-time
|
A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow an attacker to execute code via crafted Concise Binary Object Representation (CB…
|
CWE-787 CWE-755 CWE-908
Out-of-bounds Write Improper Handling of Exceptional Conditions Use of Uninitialized Resource
|
CVE-2020-24753
|
2024-11-21 14:16 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208553
|
8.8 |
HIGH
Network
|
sylabs opensuse
|
singularity leap
|
Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-25040
|
2024-11-21 14:16 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208554
|
8.1 |
HIGH
Network
|
sylabs opensuse
|
singularity leap
|
Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-25039
|
2024-11-21 14:16 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208555
|
6.5 |
MEDIUM
Network
|
genexis
|
platinum_4410_firmware
|
A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices was found to be vulnerable to Broken Access Control …
|
CWE-352
Origin Validation Error
|
CVE-2020-25015
|
2024-11-21 14:16 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208556
|
5.5 |
MEDIUM
Local
|
libraw
|
libraw
|
libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs on…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-24890
|
2024-11-21 14:16 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208557
|
7.8 |
HIGH
Local
|
libraw
|
libraw
|
A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp may lead to context-dependent arbitrary code execution.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-24889
|
2024-11-21 14:16 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208558
|
7.5 |
HIGH
Network
|
elkarbackup
|
elkarbackup
|
A Sensitive Source Code Path Disclosure vulnerability is found in ElkarBackup v1.3.3. An attacker is able to view the path of the source code jobs/sort where entire source code path is displayed in t…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-24925
|
2024-11-21 14:16 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208559
|
5.4 |
MEDIUM
Network
|
elkarbackup
|
elkarbackup
|
A Persistent Cross-site Scripting vulnerability is found in ElkarBackup v1.3.3, where an attacker can steal the user session cookie using this vulnerability present on Policies >> action >> Name Para…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24924
|
2024-11-21 14:16 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208560
|
9.8 |
CRITICAL
Network
|
yaws debian canonical
|
yaws debian_linux ubuntu_linux
|
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
|
CWE-78
OS Command
|
CVE-2020-24916
|
2024-11-21 14:16 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|