|
209571
|
7.5 |
HIGH
Network
|
lua
|
lua
|
ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-24369
|
2024-11-21 14:14 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209572
|
8.8 |
HIGH
Network
|
shopxo
|
shopxo
|
ShopXO v1.8.1 has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands and gain control of the server.
|
CWE-78
OS Command
|
CVE-2020-24220
|
2024-11-21 14:14 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209573
|
9.8 |
CRITICAL
Network
|
online_shopping_alphaware_project
|
online_shopping_alphaware
|
A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to bypass the authentication process via email and password parameters.
|
CWE-89
SQL Injection
|
CVE-2020-24208
|
2024-11-21 14:14 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209574
|
9.8 |
CRITICAL
Network
|
snmptt debian
|
snmptt debian_linux
|
SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.
|
CWE-273
Improper Check for Dropped Privileges
|
CVE-2020-24361
|
2024-11-21 14:14 |
2020-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209575
|
5.5 |
MEDIUM
Local
|
f5
|
njs
|
njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor considers the issue to be "fluff" in the NGINX use case because there is no remote …
|
CWE-416
Use After Free
|
CVE-2020-24349
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209576
|
5.5 |
MEDIUM
Local
|
f5
|
njs
|
njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-24348
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209577
|
5.5 |
MEDIUM
Local
|
f5
|
njs
|
njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_lvlhsh_level_find in njs_lvlhsh.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-24347
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209578
|
7.8 |
HIGH
Local
|
f5
|
njs
|
njs through 0.4.3, used in NGINX, has a use-after-free in njs_json_parse_iterator_call in njs_json.c.
|
CWE-416
Use After Free
|
CVE-2020-24346
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209579
|
7.8 |
HIGH
Local
|
jerryscript
|
jerryscript
|
JerryScript through 2.3.0 allows stack consumption via function a(){new new Proxy(a,{})}JSON.parse("[]",a). NOTE: the vendor states that the problem is the lack of the --stack-limit option
|
CWE-787
Out-of-bounds Write
|
CVE-2020-24345
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209580
|
7.1 |
HIGH
Local
|
jerryscript
|
jerryscript
|
JerryScript through 2.3.0 has a (function({a=arguments}){const arguments}) buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-24344
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|