Show filters
545 Total Results
Displaying 191-200 of 545
Sort by:
Attacker Value
Unknown

CVE-2020-35729

Disclosure Date: December 27, 2020 (last updated February 22, 2025)
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
Attacker Value
Unknown

CVE-2020-29596

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
MiniWeb HTTP server 0.8.19 allows remote attackers to cause a denial of service (daemon crash) via a long name for the first parameter in a POST request.
Attacker Value
Unknown

CVE-2020-25708

Disclosure Date: November 27, 2020 (last updated February 22, 2025)
A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a floating point exception, resulting in a denial of service.
Attacker Value
Unknown

CVE-2020-26133

Disclosure Date: October 28, 2020 (last updated February 22, 2025)
An issue was discovered in Dual DHCP DNS Server 7.40. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by replacing the DualServer.exe binary.
Attacker Value
Unknown

CVE-2020-26131

Disclosure Date: October 28, 2020 (last updated February 22, 2025)
Issues were discovered in Open DHCP Server (Regular) 1.75 and Open DHCP Server (LDAP Based) 0.1Beta. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by replacing the OpenDHCPServer.exe (Regular) or the OpenDHCPLdap.exe (LDAP Based) binary.
Attacker Value
Unknown

CVE-2020-26130

Disclosure Date: October 28, 2020 (last updated February 22, 2025)
Issues were discovered in Open TFTP Server multithreaded 1.66 and Open TFTP Server single port 1.66. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by replacing the OpenTFTPServerMT.exe or the OpenTFTPServerSP.exe binary.
Attacker Value
Unknown

CVE-2020-26132

Disclosure Date: October 28, 2020 (last updated February 22, 2025)
An issue was discovered in Home DNS Server 0.10. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by replacing the HomeDNSServer.exe binary.
Attacker Value
Unknown

CVE-2017-18924

Disclosure Date: October 04, 2020 (last updated February 22, 2025)
oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is similar to CVE-2020-7692. NOTE: the vendor states 'As RFC7636 is an extension, I think the claim in the Readme of "RFC 6749 compliant" is valid and not misleading and I also therefore wouldn't describe this as a "vulnerability" with the library per se.
Attacker Value
Unknown

CVE-2020-15135

Disclosure Date: August 04, 2020 (last updated February 21, 2025)
save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Tokens etc.). The fix introduced in version version 1.05 unintentionally breaks uploading so version v1.0.7 is the fixed version. This is patched by implementing Double submit. The CSRF attack would require you to navigate to a malicious site while you have an active session with Save-Server (Session key stored in cookies). The malicious user would then be able to perform some actions, including uploading/deleting files and adding redirects. If you are logged in as root, this attack is significantly more severe. They can in addition create, delete and update users. If they updated the password of a user, that user's files would then be available. If the root password is updated, all files would be visible if they logged in with the new password. Note that due to the same origin policy malicious actors cannot view the gallery or the response of any of the methods, nor be s…
Attacker Value
Unknown

CVE-2020-7686

Disclosure Date: July 25, 2020 (last updated February 21, 2025)
This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function.