Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-35133PUBLISHED: 2020-12-16irfanView 4.56 contains an error processing parsing files of type .pcx. Which leads to out-of-bounds writing at i_view32+0xdb60.
CVE-2020-7781PUBLISHED: 2020-12-16This affects the package connection-tester before 0.2.1.
The injection point is located in line 15 in index.js.
The following PoC demonstrates the vulnerability:
CVE-2019-14479PUBLISHED: 2020-12-16AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution. In the NetCrunch web client, a read-only administrator can execute arbitrary code on the server running the NetCrunch server software.
CVE-2019-14481PUBLISHED: 2020-12-16AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successful exploitation requires a logged-in user to open a malicious page and leads to account takeover.
CVE-2020-7837PUBLISHED: 2020-12-16
An issue was discovered in ML Report Program. There is a stack-based buffer overflow in function sub_41EAF0 at MLReportDeamon.exe. The function will call vsprintf without checking the length of strings in parameters given by attacker. And it finally leads to a stack-based buffer overflow via access ...