Show filters
57 Total Results
Displaying 31-40 of 57
Sort by:
Attacker Value
Unknown
CVE-2020-13901
Disclosure Date: June 10, 2020 (last updated February 21, 2025)
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_merge in sdp.c has a stack-based buffer overflow.
0
Attacker Value
Unknown
CVE-2020-10573
Disclosure Date: March 14, 2020 (last updated February 21, 2025)
An issue was discovered in Janus through 0.9.1. janus_audiobridge.c has a double mutex unlock when listing private rooms in AudioBridge.
0
Attacker Value
Unknown
CVE-2020-10577
Disclosure Date: March 14, 2020 (last updated February 21, 2025)
An issue was discovered in Janus through 0.9.1. janus.c has multiple concurrent threads that misuse the source property of a session, leading to a race condition when claiming sessions.
0
Attacker Value
Unknown
CVE-2020-10575
Disclosure Date: March 14, 2020 (last updated February 21, 2025)
An issue was discovered in Janus through 0.9.1. plugins/janus_videocall.c in the VideoCall plugin mishandles session management because a race condition causes some references to be freed too early or too many times.
0
Attacker Value
Unknown
CVE-2020-10574
Disclosure Date: March 14, 2020 (last updated February 21, 2025)
An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "query_logger" Admin API request, because of a typo in the JSON validation.
0
Attacker Value
Unknown
CVE-2020-10576
Disclosure Date: March 14, 2020 (last updated February 21, 2025)
An issue was discovered in Janus through 0.9.1. plugins/janus_voicemail.c in the VoiceMail plugin has a race condition that could cause a server crash.
0
Attacker Value
Unknown
CVE-2018-18753
Disclosure Date: October 29, 2018 (last updated November 27, 2024)
Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.
0
Attacker Value
Unknown
CVE-2018-13832
Disclosure Date: July 16, 2018 (last updated November 27, 2024)
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via Apple-Text, GIF-Text, ICO-Text, PNG-Text, or JPG-Text.
0
Attacker Value
Unknown
CVE-2014-1835
Disclosure Date: February 02, 2018 (last updated November 26, 2024)
The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to steal the login credentials by watching the process table.
0
Attacker Value
Unknown
CVE-2014-1834
Disclosure Date: February 02, 2018 (last updated November 26, 2024)
The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to inject arbitrary code by adding a semi-colon in their username or password.
0