Show filters
341 Total Results
Displaying 81-90 of 341
Sort by:
Attacker Value
Unknown
CVE-2021-21363
Disclosure Date: March 11, 2021 (last updated February 22, 2025)
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory. This vulnerability is local privilege escalation because the contents of the `outputFolder` can be appended to by an attacker. As such, code written to this directory, when executed can be attacker controlled. For more details refer to the referenced GitHub Security Advisory. This vulnerability is fixed in version 2.4.19. Note this is a distinct vulnerability from CVE-2021-21364.
0
Attacker Value
Unknown
CVE-2020-36254
Disclosure Date: February 25, 2021 (last updated November 28, 2024)
scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685.
0
Attacker Value
Unknown
CVE-2020-26118
Disclosure Date: January 11, 2021 (last updated February 22, 2025)
In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vulnerability. The application's UpdateMemento class accepts a serialized Java object directly from the user without properly sanitizing it. A malicious object can be submitted to the server via an authenticated attacker to execute commands on the underlying system.
0
Attacker Value
Unknown
CVE-2020-35904
Disclosure Date: December 31, 2020 (last updated November 28, 2024)
An issue was discovered in the crossbeam-channel crate before 0.4.4 for Rust. It has incorrect expectations about the relationship between the memory allocation and how many iterator elements there are.
0
Attacker Value
Unknown
CVE-2019-12953
Disclosure Date: December 30, 2020 (last updated February 22, 2025)
Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that may lead to revealing valid usernames, a different issue than CVE-2018-15599.
0
Attacker Value
Unknown
CVE-2020-15254
Disclosure Date: October 16, 2020 (last updated February 22, 2025)
Crossbeam is a set of tools for concurrent programming. In crossbeam-channel before version 0.4.4, the bounded channel incorrectly assumes that `Vec::from_iter` has allocated capacity that same as the number of iterator elements. `Vec::from_iter` does not actually guarantee that and may allocate extra memory. The destructor of the `bounded` channel reconstructs `Vec` from the raw pointer based on the incorrect assumes described above. This is unsound and causing deallocation with the incorrect capacity when `Vec::from_iter` has allocated different sizes with the number of iterator elements. This has been fixed in crossbeam-channel 0.4.4.
0
Attacker Value
Unknown
CVE-2013-7489
Disclosure Date: June 26, 2020 (last updated February 21, 2025)
The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2020-12835
Disclosure Date: May 20, 2020 (last updated February 21, 2025)
An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol component.
0
Attacker Value
Unknown
CVE-2020-12079
Disclosure Date: April 23, 2020 (last updated February 21, 2025)
Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-pollution attack against the Electron internal messaging API.
0
Attacker Value
Unknown
CVE-2013-0803
Disclosure Date: February 11, 2020 (last updated February 21, 2025)
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code.
0