Show filters
736 Total Results
Displaying 201-210 of 736
Sort by:
Attacker Value
Unknown

CVE-2020-7044

Disclosure Date: January 16, 2020 (last updated February 21, 2025)
In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors.
Attacker Value
Unknown

CVE-2020-7106

Disclosure Date: January 16, 2020 (last updated February 21, 2025)
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).
Attacker Value
Unknown

CVE-2019-19547

Disclosure Date: January 13, 2020 (last updated February 21, 2025)
Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issue. XSS is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. An XSS vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy.
Attacker Value
Unknown

CVE-2020-6851

Disclosure Date: January 13, 2020 (last updated February 21, 2025)
OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.
Attacker Value
Unknown

CVE-2020-6377

Disclosure Date: January 10, 2020 (last updated February 21, 2025)
Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Attacker Value
Unknown

CVE-2020-6750

Disclosure Date: January 09, 2020 (last updated November 08, 2023)
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.
Attacker Value
Unknown

CVE-2019-5188

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
Attacker Value
Unknown

CVE-2020-5311

Disclosure Date: January 03, 2020 (last updated February 21, 2025)
libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
Attacker Value
Unknown

CVE-2020-5310

Disclosure Date: January 03, 2020 (last updated February 21, 2025)
libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.
Attacker Value
Unknown

CVE-2020-5312

Disclosure Date: January 03, 2020 (last updated February 21, 2025)
libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.