Show filters
57 Total Results
Displaying 31-40 of 57
Sort by:
Attacker Value
Unknown

CVE-2020-13901

Disclosure Date: June 10, 2020 (last updated February 21, 2025)
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_merge in sdp.c has a stack-based buffer overflow.
Attacker Value
Unknown

CVE-2020-10573

Disclosure Date: March 14, 2020 (last updated February 21, 2025)
An issue was discovered in Janus through 0.9.1. janus_audiobridge.c has a double mutex unlock when listing private rooms in AudioBridge.
Attacker Value
Unknown

CVE-2020-10577

Disclosure Date: March 14, 2020 (last updated February 21, 2025)
An issue was discovered in Janus through 0.9.1. janus.c has multiple concurrent threads that misuse the source property of a session, leading to a race condition when claiming sessions.
Attacker Value
Unknown

CVE-2020-10575

Disclosure Date: March 14, 2020 (last updated February 21, 2025)
An issue was discovered in Janus through 0.9.1. plugins/janus_videocall.c in the VideoCall plugin mishandles session management because a race condition causes some references to be freed too early or too many times.
Attacker Value
Unknown

CVE-2020-10574

Disclosure Date: March 14, 2020 (last updated February 21, 2025)
An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "query_logger" Admin API request, because of a typo in the JSON validation.
Attacker Value
Unknown

CVE-2020-10576

Disclosure Date: March 14, 2020 (last updated February 21, 2025)
An issue was discovered in Janus through 0.9.1. plugins/janus_voicemail.c in the VoiceMail plugin has a race condition that could cause a server crash.
Attacker Value
Unknown

CVE-2018-18753

Disclosure Date: October 29, 2018 (last updated November 27, 2024)
Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.
0
Attacker Value
Unknown

CVE-2018-13832

Disclosure Date: July 16, 2018 (last updated November 27, 2024)
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via Apple-Text, GIF-Text, ICO-Text, PNG-Text, or JPG-Text.
0
Attacker Value
Unknown

CVE-2014-1835

Disclosure Date: February 02, 2018 (last updated November 26, 2024)
The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to steal the login credentials by watching the process table.
0
Attacker Value
Unknown

CVE-2014-1834

Disclosure Date: February 02, 2018 (last updated November 26, 2024)
The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to inject arbitrary code by adding a semi-colon in their username or password.
0