|
209751
|
7.5 |
HIGH
Network
|
axiosys
|
bento4
|
A WRITE memory access in the AP4_NullTerminatedStringAtom::AP4_NullTerminatedStringAtom component of Bento4 version 06c39d9 can lead to a segmentation fault.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-23334
|
2024-11-21 14:13 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209752
|
7.5 |
HIGH
Network
|
axiosys
|
bento4
|
A heap-based buffer overflow exists in the AP4_CttsAtom::AP4_CttsAtom component located in /Core/Ap4Utils.h of Bento4 version 06c39d9. This can lead to a denial of service (DOS).
|
CWE-787
Out-of-bounds Write
|
CVE-2020-23333
|
2024-11-21 14:13 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209753
|
7.5 |
HIGH
Network
|
axiosys
|
bento4
|
A heap-based buffer overflow exists in the AP4_StdcFileByteStream::ReadPartial component located in /StdC/Ap4StdCFileByteStream.cpp of Bento4 version 06c39d9. This issue can lead to a denial of servi…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-23332
|
2024-11-21 14:13 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209754
|
7.5 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_DescriptorListWriter::Action component located in /Core/Ap4Descriptor.h. It allows an attacker to cause…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-23331
|
2024-11-21 14:13 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209755
|
7.5 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_Stz2Atom::GetSampleSize component located in /Core/Ap4Stz2Atom.cpp. It allows an attacker to cause a de…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-23330
|
2024-11-21 14:13 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209756
|
9.8 |
CRITICAL
Network
|
phome
|
empirecms
|
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.
|
CWE-94
Code Injection
|
CVE-2020-22937
|
2024-11-21 14:13 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209757
|
8.8 |
HIGH
Network
|
express-cart_project
|
express-cart
|
Cross Site Request Forgery (CSRF) vulnerability in Express cart v1.1.16 allows attackers to add an administrator account, add discount code or other unspecified impacts.
|
CWE-352
Origin Validation Error
|
CVE-2020-22403
|
2024-11-21 14:13 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209758
|
5.5 |
MEDIUM
Local
|
kuba_project
|
kuba
|
A vulnerability in all versions of Kuba allows attackers to overwrite arbitrary files in arbitrary directories with crafted Zip files due to improper validation of file paths in .zip archives.
|
CWE-22
Path Traversal
|
CVE-2020-23172
|
2024-11-21 14:13 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209759
|
5.5 |
MEDIUM
Local
|
nim-lang
|
nim-lang
|
A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via a crafted zip file with dot-slash characters included in the name of the craft…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2020-23171
|
2024-11-21 14:13 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209760
|
9.8 |
CRITICAL
Network
|
rconfig
|
rconfig
|
rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed directly to the exec function without being escaped.
|
CWE-78
OS Command
|
CVE-2020-23151
|
2024-11-21 14:13 |
2021-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|