Show filters
203 Total Results
Displaying 161-170 of 203
Sort by:
Attacker Value
Unknown
CVE-2020-16253
Disclosure Date: August 05, 2020 (last updated February 21, 2025)
The PgHero gem through 2.6.0 for Ruby allows CSRF.
0
Attacker Value
Unknown
CVE-2020-12845
Disclosure Date: July 27, 2020 (last updated February 21, 2025)
Cherokee 0.4.27 to 1.2.104 is affected by a denial of service due to a NULL pointer dereferences. A remote unauthenticated attacker can crash the server by sending an HTTP request to protected resources using a malformed Authorization header that is mishandled during a cherokee_buffer_add call within cherokee_validator_parse_basic or cherokee_validator_parse_digest.
0
Attacker Value
Unknown
CVE-2020-11613
Disclosure Date: June 11, 2020 (last updated February 21, 2025)
Mids' Reborn Hero Designer 2.6.0.7 has an elevation of privilege vulnerability due to default and insecure permissions being set for the installation folder. By default, the Authenticated Users group has Modify permissions to the installation folder. Because of this, any user on the system can replace binaries or plant malicious DLLs to obtain elevated, or different, privileges, depending on the context of the user that runs the application.
0
Attacker Value
Unknown
CVE-2020-11614
Disclosure Date: June 11, 2020 (last updated February 21, 2025)
Mids' Reborn Hero Designer 2.6.0.7 downloads the update manifest, as well as update files, over cleartext HTTP. Additionally, the application does not perform file integrity validation for files after download. An attacker can perform a man-in-the-middle attack against this connection and replace executable files with malicious versions, which the operating system then executes under the context of the user running Hero Designer.
0
Attacker Value
Unknown
CVE-2019-20800
Disclosure Date: May 18, 2020 (last updated February 21, 2025)
In Cherokee through 1.2.104, remote attackers can trigger an out-of-bounds write in cherokee_handler_cgi_add_env_pair in handler_cgi.c by sending many request headers, as demonstrated by a GET request with many "Host: 127.0.0.1" headers.
0
Attacker Value
Unknown
CVE-2019-20799
Disclosure Date: May 18, 2020 (last updated February 21, 2025)
In Cherokee through 1.2.104, multiple memory corruption errors may be used by a remote attacker to destabilize the work of a server.
0
Attacker Value
Unknown
CVE-2019-20798
Disclosure Date: May 18, 2020 (last updated February 21, 2025)
An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displayed on the About page in the default configuration of the web server and its administrator panel. The XSS in the administrator panel can be used to reconfigure the server and execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2020-1964
Disclosure Date: April 16, 2020 (last updated February 21, 2025)
It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerabilities (CWE-502: Deserialization of Untrusted Data).
0
Attacker Value
Unknown
CVE-2020-7634
Disclosure Date: April 06, 2020 (last updated February 21, 2025)
heroku-addonpool through 0.1.15 is vulnerable to Command Injection.
0
Attacker Value
Unknown
CVE-2019-19134
Disclosure Date: February 26, 2020 (last updated February 21, 2025)
The Hero Maps Premium plugin 2.2.1 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index.php p parameter because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to inject HTML or arbitrary JavaScript within the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based tokens or to launch other attacks.
0