Search Results (18930 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-7852 2 Hmtalk, Microsoft 2 Daviewindy, Windows 2024-11-21 7.8 High
DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed ex.j2c format file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.
CVE-2020-7845 1 Jiransecurity 1 Spamsniper 2024-11-21 8.1 High
Spamsniper 5.0 ~ 5.2.7 contain a stack-based buffer overflow vulnerability caused by improper boundary checks when parsing MAIL FROM command. It leads remote attacker to execute arbitrary code via crafted packet.
CVE-2020-7837 1 Polarisoffice 1 Polaris Ml Report 2024-11-21 7.5 High
An issue was discovered in ML Report Program. There is a stack-based buffer overflow in function sub_41EAF0 at MLReportDeamon.exe. The function will call vsprintf without checking the length of strings in parameters given by attacker. And it finally leads to a stack-based buffer overflow via access to crafted web page. This issue affects: Infraware ML Report 2.19.312.0000.
CVE-2020-7836 1 Voiceye Wsactivebridgees Project 1 Voiceye Wsactivebridges 2024-11-21 7.8 High
VOICEYE WSActiveBridgeES versions prior to 2.1.0.3 contains a stack-based buffer overflow vulnerability caused by improper bound checking parameter given by attack. It finally leads to a stack-based buffer overflow via access to crafted web page.
CVE-2020-7829 2 Hmtalk, Microsoft 2 Daviewindy, Windows 2024-11-21 7.8 High
DaviewIndy 8.98.4 and earlier version contain Heap-based overflow vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.
CVE-2020-7828 2 Hmtalk, Microsoft 2 Daviewindy, Windows 2024-11-21 7.8 High
DaviewIndy 8.98.4 and earlier version contain Heap-based overflow vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.
CVE-2020-7825 1 Tobesoft 1 Miplatform 2024-11-21 8.8 High
A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An attacker could execute arbitrary remote command by sending parameters to WinExec function in ExtCommandApi.dll module of MiPlatform.
CVE-2020-7823 1 Hmtalk 1 Daviewindy 2024-11-21 7.8 High
DaviewIndy has a Memory corruption vulnerability, triggered when the user opens a malformed image file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.
CVE-2020-7822 2 Hmtalk, Microsoft 2 Daviewindy, Windows 2024-11-21 7.8 High
DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed image file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.
CVE-2020-7818 1 Hmtalk 1 Daviewindy 2024-11-21 7.8 High
DaviewIndy 8.98.9 and earlier has a Heap-based overflow vulnerability, triggered when the user opens a malformed PDF file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.
CVE-2020-7805 1 Infomark 4 Iml500, Iml500 Firmware, Iml520 and 1 more 2024-11-21 9.8 Critical
An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This issue is a command injection allowing attackers to execute arbitrary OS commands.
CVE-2020-7804 2 Handysoft, Microsoft 4 Groupware, Windows 10, Windows 7 and 1 more 2024-11-21 6.4 Medium
ActiveX Control(HShell.dll) in Handy Groupware 1.7.3.1 for Windows 7, 8, and 10 allows an attacker to execute arbitrary command via the ShellExec method.
CVE-2020-7794 1 Buns Project 1 Buns 2024-11-21 9.8 Critical
This affects all versions of package buns. The injection point is located in line 678 in index file lib/index.js in the exported function install(requestedModule).
CVE-2020-7789 2 Node-notifier Project, Redhat 2 Node-notifier, Ansible Automation Platform 2024-11-21 5.6 Medium
This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines due to the options params not being sanitised when being passed an array.
CVE-2020-7786 1 Macfromip Project 1 Macfromip 2024-11-21 9.8 Critical
This affects all versions of package macfromip. The injection point is located in line 66 in macfromip.js.
CVE-2020-7785 1 Node-ps Project 1 Node-ps 2024-11-21 9.8 Critical
This affects all versions of package node-ps. The injection point is located in line 72 in lib/index.js.
CVE-2020-7784 1 Ts-process-promises Project 1 Ts-process-promises 2024-11-21 9.8 Critical
This affects all versions of package ts-process-promises. The injection point is located in line 45 in main entry of package in lib/process-promises.js. The vulnerability is demonstrated with the following PoC:
CVE-2020-7782 1 Spritesheet-js Project 1 Spritesheet-js 2024-11-21 9.8 Critical
This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection point is located in line 32 in lib/generator.js, which is triggered by main entry of the package.
CVE-2020-7781 1 Connection-tester Project 1 Connection-tester 2024-11-21 9.8 Critical
This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vulnerability:
CVE-2020-7778 1 Systeminformation 1 Systeminformation 2024-11-21 7.3 High
This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands.