CVE-2020-7106
- EPSS 4.09%
- Published 16.01.2020 04:15:11
- Last modified 21.11.2024 05:36:38
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string fr...
CVE-2020-6377
- EPSS 2.9%
- Published 10.01.2020 22:15:12
- Last modified 21.11.2024 05:35:36
Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-13767
- EPSS 7.42%
- Published 10.01.2020 22:15:11
- Last modified 21.11.2024 04:25:41
Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-1765
- EPSS 0.87%
- Published 10.01.2020 15:15:11
- Last modified 21.11.2024 05:11:20
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5....
CVE-2020-6609
- EPSS 0.56%
- Published 08.01.2020 21:15:11
- Last modified 21.11.2024 05:36:01
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.
CVE-2020-6611
- EPSS 0.58%
- Published 08.01.2020 21:15:11
- Last modified 21.11.2024 05:36:01
GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c.
CVE-2020-6612
- EPSS 0.61%
- Published 08.01.2020 21:15:11
- Last modified 21.11.2024 05:36:01
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.
CVE-2020-6613
- EPSS 0.61%
- Published 08.01.2020 21:15:11
- Last modified 21.11.2024 05:36:01
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.
CVE-2020-6614
- EPSS 0.61%
- Published 08.01.2020 21:15:11
- Last modified 21.11.2024 05:36:02
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
CVE-2020-6615
- EPSS 0.67%
- Published 08.01.2020 21:15:11
- Last modified 21.11.2024 05:36:02
GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl).