Show filters
548 Total Results
Displaying 211-220 of 548
Sort by:
Attacker Value
Unknown
CVE-2020-10188 — Junos OS: Arbitrary code execution vulnerability in Telnet ser…
Disclosure Date: March 06, 2020 (last updated February 21, 2025)
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
0
Attacker Value
Unknown
CVE-2020-9402
Disclosure Date: March 05, 2020 (last updated February 21, 2025)
Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject malicious SQL.
0
Attacker Value
Unknown
CVE-2020-10029
Disclosure Date: March 04, 2020 (last updated February 21, 2025)
The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.
0
Attacker Value
Unknown
CVE-2020-9274
Disclosure Date: February 26, 2020 (last updated February 21, 2025)
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member. This is related to init_aliases in diraliases.c.
0
Attacker Value
Unknown
CVE-2020-8130
Disclosure Date: February 24, 2020 (last updated February 21, 2025)
There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.
0
Attacker Value
Unknown
CVE-2020-9308
Disclosure Date: February 20, 2020 (last updated February 21, 2025)
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact.
0
Attacker Value
Unknown
CVE-2020-6062
Disclosure Date: February 19, 2020 (last updated February 21, 2025)
An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to send an HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2020-6061
Disclosure Date: February 19, 2020 (last updated February 21, 2025)
An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2018-14553
Disclosure Date: February 11, 2020 (last updated February 21, 2025)
gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).
0
Attacker Value
Unknown
CVE-2019-12528
Disclosure Date: February 04, 2020 (last updated November 08, 2023)
An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes.
0