CVE-2020-10756
- EPSS 0.03%
- Veröffentlicht 09.07.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:56:00
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious...
CVE-2019-14900
- EPSS 1.41%
- Veröffentlicht 06.07.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:27:38
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. Th...
CVE-2020-10753
- EPSS 0.41%
- Veröffentlicht 26.06.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:59
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file genera...
CVE-2020-10711
- EPSS 5.08%
- Veröffentlicht 22.05.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:54
A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the...
CVE-2020-1758
- EPSS 0.25%
- Veröffentlicht 15.05.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:19
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.
CVE-2020-10685
- EPSS 0.14%
- Veröffentlicht 11.05.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:51
A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when using modules which decrypts...
CVE-2020-1759
- EPSS 0.41%
- Veröffentlicht 13.04.2020 13:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:19
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and pote...
CVE-2019-14905
- EPSS 0.05%
- Veröffentlicht 31.03.2020 17:15:26
- Zuletzt bearbeitet 21.11.2024 04:27:39
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code c...
CVE-2020-10684
- EPSS 0.02%
- Veröffentlicht 24.03.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:50
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts...
CVE-2020-1738
- EPSS 0.14%
- Veröffentlicht 16.03.2020 16:15:14
- Zuletzt bearbeitet 21.11.2024 05:11:16
A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file...