Show filters
545 Total Results
Displaying 201-210 of 545
Sort by:
Attacker Value
Unknown
CVE-2020-7683
Disclosure Date: July 25, 2020 (last updated February 21, 2025)
This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function.
0
Attacker Value
Unknown
CVE-2020-8214
Disclosure Date: July 20, 2020 (last updated February 21, 2025)
A path traversal vulnerability in servey version < 3 allows an attacker to read content of any arbitrary file.
0
Attacker Value
Unknown
CVE-2020-7684
Disclosure Date: July 17, 2020 (last updated February 21, 2025)
This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation.
0
Attacker Value
Unknown
CVE-2020-15500
Disclosure Date: July 01, 2020 (last updated February 21, 2025)
An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS.
0
Attacker Value
Unknown
CVE-2017-18922
Disclosure Date: June 30, 2020 (last updated February 21, 2025)
It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2020-14399
Disclosure Date: June 17, 2020 (last updated February 21, 2025)
An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_t pointers in libvncclient/rfbproto.c. NOTE: there is reportedly "no trust boundary crossed.
0
Attacker Value
Unknown
CVE-2020-14400
Disclosure Date: June 17, 2020 (last updated February 21, 2025)
An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. NOTE: Third parties do not consider this to be a vulnerability as there is no known path of exploitation or cross of a trust boundary
0
Attacker Value
Unknown
CVE-2020-14401
Disclosure Date: June 17, 2020 (last updated February 21, 2025)
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow.
0
Attacker Value
Unknown
CVE-2018-21246
Disclosure Date: June 15, 2020 (last updated February 21, 2025)
Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
0
Attacker Value
Unknown
CVE-2020-13111
Disclosure Date: May 16, 2020 (last updated February 21, 2025)
NaviServer 4.99.4 to 4.99.19 allows denial of service due to the nsd/driver.c ChunkedDecode function not properly validating the length of a chunk. A remote attacker can craft a chunked-transfer request that will result in a negative value being passed to memmove via the size parameter, causing the process to crash.
0