CVE-2020-27776
- EPSS 0.05%
- Published 04.12.2020 21:15:12
- Last modified 21.11.2024 05:21:48
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type unsigned long. This would most likely ...
CVE-2020-27765
- EPSS 0.06%
- Published 04.12.2020 15:15:10
- Last modified 21.11.2024 05:21:47
A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to applic...
CVE-2020-27767
- EPSS 0.06%
- Published 04.12.2020 15:15:10
- Last modified 21.11.2024 05:21:47
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of types `float` and `unsigned char`. This would...
CVE-2020-27771
- EPSS 0.07%
- Published 04.12.2020 15:15:10
- Last modified 21.11.2024 05:21:48
In RestoreMSCWarning() of /coders/pdf.c there are several areas where calls to GetPixelIndex() could result in values outside the range of representable for the unsigned char type. The patch casts the return value of GetPixelIndex() to ssize_t type t...
CVE-2020-27778
- EPSS 0.29%
- Published 03.12.2020 17:15:13
- Last modified 21.11.2024 05:21:49
A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a deni...
CVE-2020-27783
- EPSS 1.14%
- Published 03.12.2020 17:15:13
- Last modified 21.11.2024 05:21:49
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbit...
CVE-2020-14339
- EPSS 0.07%
- Published 03.12.2020 17:15:12
- Last modified 21.11.2024 05:03:02
A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest ...
CVE-2020-14351
- EPSS 0.03%
- Published 03.12.2020 17:15:12
- Last modified 21.11.2024 05:03:04
A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission to monitor perf events to corrupt memory and possibly escalate privileges. The highest threat from this vulne...
CVE-2020-14318
- EPSS 0.19%
- Published 03.12.2020 16:15:12
- Last modified 21.11.2024 05:02:59
A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.
CVE-2020-14383
- EPSS 0.27%
- Published 02.12.2020 01:15:12
- Last modified 21.11.2024 05:03:08
A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server, which also serves protocols other than dnsserver, will be restarted after a short delay, but it is easy for an authenticate...