Show filters
185 Total Results
Displaying 81-90 of 185
Sort by:
Attacker Value
Unknown

CVE-2021-3281

Disclosure Date: February 02, 2021 (last updated February 22, 2025)
In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal via an archive with absolute paths or relative paths with dot segments.
Attacker Value
Unknown

CVE-2020-16160

Disclosure Date: October 19, 2020 (last updated February 22, 2025)
GoPro gpmf-parser 1.5 has a division-by-zero vulnerability in GPMF_Decompress(). Parsing malicious input can result in a crash.
Attacker Value
Unknown

CVE-2020-16158

Disclosure Date: October 19, 2020 (last updated February 22, 2025)
GoPro gpmf-parser through 1.5 has a stack out-of-bounds write vulnerability in GPMF_ExpandComplexTYPE(). Parsing malicious input can result in a crash or potentially arbitrary code execution.
Attacker Value
Unknown

CVE-2020-16161

Disclosure Date: October 19, 2020 (last updated February 22, 2025)
GoPro gpmf-parser 1.5 has a division-by-zero vulnerability in GPMF_ScaledData(). Parsing malicious input can result in a crash.
Attacker Value
Unknown

CVE-2020-16159

Disclosure Date: October 19, 2020 (last updated February 22, 2025)
GoPro gpmf-parser 1.5 has a heap out-of-bounds read and segfault in GPMF_ScaledData(). Parsing malicious input can result in a crash or information disclosure.
Attacker Value
Unknown

CVE-2020-24213

Disclosure Date: September 23, 2020 (last updated February 22, 2025)
An integer overflow was discovered in YGOPro ygocore v13.51. Attackers can use it to leak the game server thread's memory.
Attacker Value
Unknown

CVE-2020-24584

Disclosure Date: September 01, 2020 (last updated February 22, 2025)
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.
Attacker Value
Unknown

CVE-2020-24583

Disclosure Date: September 01, 2020 (last updated February 22, 2025)
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level directories created in the process of uploading files. It was also not applied to intermediate-level collected static directories when using the collectstatic management command.
Attacker Value
Unknown

CVE-2020-13254

Disclosure Date: June 03, 2020 (last updated February 21, 2025)
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.
Attacker Value
Unknown

CVE-2020-13596

Disclosure Date: June 03, 2020 (last updated February 21, 2025)
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.