|
210471
|
9.8 |
CRITICAL
Network
|
facebook
|
hhvm
|
xbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to the generated string, but was not using its standard append char function. As a result, if the buf…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-1917
|
2024-11-21 14:11 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210472
|
9.8 |
CRITICAL
Network
|
facebook
|
hhvm
|
An incorrect size calculation in ldap_escape may lead to an integer overflow when overly long input is passed in, resulting in an out-of-bounds write. This issue affects HHVM prior to 4.56.2, all ver…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-1916
|
2024-11-21 14:11 |
2021-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210473
|
6.1 |
MEDIUM
Network
|
apache
|
ambari
|
A cross-site scripting issue was found in Apache Ambari Views. This was addressed in Apache Ambari 2.7.4.
|
CWE-79
Cross-site Scripting
|
CVE-2020-1936
|
2024-11-21 14:11 |
2021-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210474
|
2.7 |
LOW
Network
|
redhat
|
keycloak single_sign-on jboss_fuse openshift_application_runtimes
|
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-1717
|
2024-11-21 14:11 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210475
|
4.9 |
MEDIUM
Network
|
otrs
|
ticket_forms
|
When dynamic templates are used (OTRSTicketForms), admin can use OTRS tags which are not masked properly and can reveal sensitive information. This issue affects: OTRS AG OTRSTicketForms 6.0.x versio…
|
CWE-200
Information Exposure
|
CVE-2020-1779
|
2024-11-21 14:11 |
2021-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210476
|
7.8 |
HIGH
Local
|
whatsapp
|
whatsapp_business whatsapp
|
A missing bounds check in WhatsApp for Android prior to v2.21.1.13 and WhatsApp Business for Android prior to v2.21.1.13 could have allowed out-of-bounds read and write if a user applied specific ima…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-1910
|
2024-11-21 14:11 |
2021-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210477
|
9.8 |
CRITICAL
Network
|
facebook
|
hermes
|
A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2 (https://github.com/facebook/hermes/commit/86543ac47e59c522976b5632b8bf9a2a4…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-1896
|
2024-11-21 14:11 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210478
|
9.8 |
CRITICAL
Network
|
yccms
|
yccms
|
Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20287
|
2024-11-21 14:11 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210479
|
5.4 |
MEDIUM
Network
|
redhat
|
keycloak
|
A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access to…
|
CWE-863
Incorrect Authorization
|
CVE-2020-1725
|
2024-11-21 14:11 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210480
|
6.1 |
MEDIUM
Network
|
redhat keycloak_gatekeeper_project
|
mobile_application_platform keycloak_gatekeeper
|
A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0…
|
CWE-601
Open Redirect
|
CVE-2020-1723
|
2024-11-21 14:11 |
2021-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|