Show filters
287 Total Results
Displaying 141-150 of 287
Sort by:
Attacker Value
Unknown
CVE-2020-5147
Disclosure Date: January 09, 2021 (last updated February 22, 2025)
SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 10.2.300 and earlier.
0
Attacker Value
Unknown
CVE-2020-28852
Disclosure Date: January 02, 2021 (last updated February 22, 2025)
In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)
0
Attacker Value
Unknown
CVE-2020-29458
Disclosure Date: December 02, 2020 (last updated February 22, 2025)
Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.
0
Attacker Value
Unknown
CVE-2020-14734
Disclosure Date: October 21, 2020 (last updated November 28, 2024)
Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Text. Successful attacks of this vulnerability can result in takeover of Oracle Text. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
0
Attacker Value
Unknown
CVE-2020-27176
Disclosure Date: October 16, 2020 (last updated February 22, 2025)
Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution. NOTE: this might be considered a duplicate of CVE-2020-26870; however, it can also be considered an issue in the design of the "source code mode" feature, which parses HTML even though HTML support is not one of the primary advertised roles of the product.
0
Attacker Value
Unknown
CVE-2015-8032
Disclosure Date: August 14, 2020 (last updated February 21, 2025)
In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.
0
Attacker Value
Unknown
CVE-2015-8033
Disclosure Date: August 14, 2020 (last updated February 21, 2025)
In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.
0
Attacker Value
Unknown
CVE-2020-5131
Disclosure Date: July 17, 2020 (last updated February 21, 2025)
SonicWall NetExtender Windows client vulnerable to arbitrary file write vulnerability, this allows attacker to overwrite a DLL and execute code with the same privilege in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 9.0.815 and earlier.
0
Attacker Value
Unknown
CVE-2019-14900
Disclosure Date: July 06, 2020 (last updated February 21, 2025)
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.
0
Attacker Value
Unknown
CVE-2020-14040
Disclosure Date: June 17, 2020 (last updated February 21, 2025)
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.
0