Show filters
545 Total Results
Displaying 201-210 of 545
Sort by:
Attacker Value
Unknown

CVE-2020-7683

Disclosure Date: July 25, 2020 (last updated February 21, 2025)
This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function.
Attacker Value
Unknown

CVE-2020-8214

Disclosure Date: July 20, 2020 (last updated February 21, 2025)
A path traversal vulnerability in servey version < 3 allows an attacker to read content of any arbitrary file.
Attacker Value
Unknown

CVE-2020-7684

Disclosure Date: July 17, 2020 (last updated February 21, 2025)
This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation.
Attacker Value
Unknown

CVE-2020-15500

Disclosure Date: July 01, 2020 (last updated February 21, 2025)
An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS.
Attacker Value
Unknown

CVE-2017-18922

Disclosure Date: June 30, 2020 (last updated February 21, 2025)
It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.
Attacker Value
Unknown

CVE-2020-14399

Disclosure Date: June 17, 2020 (last updated February 21, 2025)
An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_t pointers in libvncclient/rfbproto.c. NOTE: there is reportedly "no trust boundary crossed.
Attacker Value
Unknown

CVE-2020-14400

Disclosure Date: June 17, 2020 (last updated February 21, 2025)
An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. NOTE: Third parties do not consider this to be a vulnerability as there is no known path of exploitation or cross of a trust boundary
Attacker Value
Unknown

CVE-2020-14401

Disclosure Date: June 17, 2020 (last updated February 21, 2025)
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow.
Attacker Value
Unknown

CVE-2018-21246

Disclosure Date: June 15, 2020 (last updated February 21, 2025)
Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
Attacker Value
Unknown

CVE-2020-13111

Disclosure Date: May 16, 2020 (last updated February 21, 2025)
NaviServer 4.99.4 to 4.99.19 allows denial of service due to the nsd/driver.c ChunkedDecode function not properly validating the length of a chunk. A remote attacker can craft a chunked-transfer request that will result in a negative value being passed to memmove via the size parameter, causing the process to crash.