Search Results (357840 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-26539 1 Foxitsoftware 2 Foxit Reader, Phantompdf 2024-11-21 9.8 Critical
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. When there is a multiple interpretation error for /V (in the Additional Action and Field dictionaries), a use-after-free can occur with resultant remote code execution (or an information leak).
CVE-2020-26538 1 Foxitsoftware 2 Foxit Reader, Phantompdf 2024-11-21 7.8 High
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. It allows attackers to execute arbitrary code via a Trojan horse taskkill.exe in the current working directory.
CVE-2020-26537 1 Foxitsoftware 2 Foxit Reader, Phantompdf 2024-11-21 9.8 Critical
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. In a certain Shading calculation, the number of outputs is unequal to the number of color components in a color space. This causes an out-of-bounds write.
CVE-2020-26536 1 Foxitsoftware 2 Foxit Reader, Phantompdf 2024-11-21 5.5 Medium
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is a NULL pointer dereference via a crafted PDF document.
CVE-2020-26535 1 Foxitsoftware 2 Foxit Reader, Phantompdf 2024-11-21 9.8 Critical
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate thread local storage but obtains an unacceptable index value, V8 throws an exception that leads to a write access violation (and read access violation).
CVE-2020-26534 1 Foxitsoftware 2 Foxit Reader, Phantompdf 2024-11-21 9.8 Critical
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::DeleteOptions, during AcroForm JavaScript execution.
CVE-2020-26527 1 Damstratechnology 1 Smart Asset 2024-11-21 9.8 Critical
An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7. Cross-origin resource sharing trusts random origins by accepting the arbitrary 'Origin: example.com' header and responding with 200 OK and a wildcard 'Access-Control-Allow-Origin: *' header.
CVE-2020-26526 1 Damstratechnology 1 Smart Asset 2024-11-21 5.3 Medium
An issue was discovered in Damstra Smart Asset 2020.7. It is possible to enumerate valid usernames on the login page. The application sends a different server response when the username is invalid than when the username is valid ("Unable to find an APIDomain" versus "Wrong email or password").
CVE-2020-26525 1 Damstratechnology 1 Smart Asset 2024-11-21 9.1 Critical
Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the database and server to initiate remote connections to third party DNS servers.
CVE-2020-26524 1 Filecloud 1 Filecloud 2024-11-21 5.3 Medium
CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.
CVE-2020-26523 1 Froala 1 Froala Editor 2024-11-21 6.1 Medium
Froala Editor before 3.2.2 allows XSS via pasted content.
CVE-2020-26522 1 Garfield Petshop Project 1 Garfield Petshop 2024-11-21 8.8 High
A cross-site request forgery (CSRF) vulnerability in mod/user/act_user.php in Garfield Petshop through 2020-10-01 allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts.
CVE-2020-26521 2 Fedoraproject, Linuxfoundation 2 Fedora, Nats-server 2024-11-21 7.5 High
The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code).
CVE-2020-26519 3 Artifex, Debian, Fedoraproject 3 Mupdf, Debian Linux, Fedora 2024-11-21 5.5 Medium
Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a denial of service.
CVE-2020-26518 1 Artica 1 Pandora Fms 2024-11-21 9.8 Critical
Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php session_id parameter.
CVE-2020-26517 1 Intland 1 Codebeamer 2024-11-21 4.8 Medium
A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. It is possible to perform XSS attacks through using the WebDAV functionality to upload files to a project (Authn users), using the users import functionality (Admin only), and changing the login text in the application configuration (Admin only).
CVE-2020-26516 1 Intland 1 Codebeamer 2024-11-21 8.8 High
A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entirely predicted allowing attackers to cause the victim's browser to execute undesired actions in the web application through crafted requests.
CVE-2020-26515 1 Intland 1 Codebeamer 2024-11-21 7.5 High
An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the application contains the encrypted user's credentials. However, due to a bug in the application code, those credentials are encrypted using a NULL encryption key.
CVE-2020-26513 1 Intland 1 Codebeamer 2024-11-21 5.5 Medium
An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM application to import projects, is parsed by insecurely configured software components, which can be abused for XML External Entity Attacks.
CVE-2020-26511 1 Wpo365 1 Wordpress \+ Azure Ad \/ Microsoft Office 365 2024-11-21 7.5 High
The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass.