5.1
CVE-2020-37079 - Wing FTP Server < 6.2.7 - Cross-site Request Forgery
Wing FTP Server versions prior to 6.2.7 contain a cross-site request forgery (CSRF) vulnerability in the web administration interface that allows attackers to delete admin users. Attackers can craft a malicious HTML page with a hidden form to submit a request that deletes the administrative user acβ¦
6.7
CVE-2020-37171 - TapinRadio 2.12.3 - 'username' Denial of Service
TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy username configuration that allows local attackers to crash the application. Attackers can overwrite the username field with 10,000 bytes of arbitrary data to trigger an application crash and prevent normal prograβ¦
6.7
CVE-2020-37170 - TapinRadio 2.12.3 - 'address' Denial of Service
TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy address configuration that allows local attackers to crash the application. Attackers can overwrite the address field with 3000 bytes of arbitrary data to trigger an application crash and prevent normal program fuβ¦
6.9
CVE-2020-37166 - AbsoluteTelnet 11.12 - 'SSH2/username' Denial of Service
AbsoluteTelnet 11.12 contains a denial of service vulnerability in the SSH2 username input field that allows local attackers to crash the application. Attackers can overwrite the username field with a 1000-byte buffer, causing the application to become unresponsive and terminate.
6.7
CVE-2020-37165 - AbsoluteTelnet 11.12 - "license name" Denial of Service
AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate a 2500-character payload and paste it into the license name field to trigger an application crash.
6.7
CVE-2020-37164 - AbsoluteTelnet 11.12 - "license entry" Denial of Service
AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate a 2500-character payload and paste it into the license entry field to trigger an application crash.
8.8
CVE-2020-37163 - QuickDate 1.3.2 - SQL Injection
QuickDate 1.3.2 contains a SQL injection vulnerability that allows remote attackers to manipulate database queries through the '_located' parameter in the find_matches endpoint. Attackers can inject UNION-based SQL statements to extract database information including user credentials, database nameβ¦
8.4
CVE-2020-37162 - Wedding Slideshow Studio 1.36 - 'Key' Buffer Overflow
Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability in the registration key input that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious payload of 1608 bytes to trigger a stack-based buffer overflow and execute commands through theβ¦
8.4
CVE-2020-37161 - Wedding Slideshow Studio 1.36 - 'Name' Buffer Overflow
Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the registration name field with malicious payload. Attackers can craft a specially designed payload to trigger remote code execution, demonstrating the ability to rβ¦
8.5
CVE-2020-37160 - SprintWork 2.3.1 - Local Privilege Escalation
SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder permissions on Windows systems. Local unprivileged users can exploit missing executable files and weak service configurations to create a new administrative user and gain completβ¦