CVE-2020-25643
- EPSS 0.39%
- Published 06.10.2020 14:15:12
- Last modified 21.11.2024 05:18:19
A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial...
CVE-2020-14370
- EPSS 0.15%
- Published 23.09.2020 13:15:15
- Last modified 21.11.2024 05:03:06
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variable...
CVE-2020-14382
- EPSS 0.28%
- Published 16.09.2020 15:15:12
- Last modified 21.11.2024 05:03:08
A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, that is effectively invoked on every device/image presenting itself as LUKS2 container. The bug is in segments validation code in fil...
- EPSS 0.01%
- Published 15.09.2020 19:15:12
- Last modified 21.11.2024 04:56:00
A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS...
CVE-2020-14331
- EPSS 0.03%
- Published 15.09.2020 19:15:12
- Last modified 21.11.2024 05:03:01
A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker attempts to resize the console, calling an ioctl VT_RESIZE, which causes an out-of-bounds write to occur. This flaw allows a local us...
CVE-2020-14346
- EPSS 0.08%
- Published 15.09.2020 19:15:12
- Last modified 29.08.2025 13:42:30
A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality ...
CVE-2020-14361
- EPSS 0.1%
- Published 15.09.2020 19:15:12
- Last modified 29.08.2025 13:42:30
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity...
CVE-2020-14362
- EPSS 0.1%
- Published 15.09.2020 19:15:12
- Last modified 29.08.2025 13:42:30
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity...
CVE-2020-0570
- EPSS 0.24%
- Published 14.09.2020 19:15:10
- Last modified 21.11.2024 04:53:46
Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.
- EPSS 20.4%
- Published 11.09.2020 17:15:18
- Last modified 21.11.2024 05:09:37
<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with th...