CVE-2020-11868
- EPSS 1.3%
- Veröffentlicht 17.04.2020 04:15:10
- Zuletzt bearbeitet 05.05.2025 17:15:57
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a vali...
CVE-2020-1730
- EPSS 0.08%
- Veröffentlicht 13.04.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:15
A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup th...
CVE-2020-11669
- EPSS 0.08%
- Veröffentlicht 10.04.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:58:21
An issue was discovered in the Linux kernel before 5.2 on the powerpc platform. arch/powerpc/kernel/idle_book3s.S does not have save/restore functionality for PNV_POWERSAVE_AMR, PNV_POWERSAVE_UAMOR, and PNV_POWERSAVE_AMOR, aka CID-53a712bae5dd.
CVE-2020-2732
- EPSS 0.44%
- Veröffentlicht 08.04.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:26:06
A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing sensitive L1 resources that shou...
CVE-2020-10696
- EPSS 0.3%
- Veröffentlicht 31.03.2020 22:15:14
- Zuletzt bearbeitet 21.11.2024 04:55:52
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user ...
CVE-2020-1712
- EPSS 0.1%
- Veröffentlicht 31.03.2020 17:15:26
- Zuletzt bearbeitet 21.11.2024 05:11:13
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially...
CVE-2019-10179
- EPSS 0.45%
- Veröffentlicht 20.03.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:35
A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a Reflected Cross Site Scripting (XSS) vulnerability. An attacker could t...
CVE-2019-10221
- EPSS 0.69%
- Veröffentlicht 20.03.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:41
A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from the pki-core server. This flaw is caused by missing sanitization of the GET URL parameters. An attacker could abuse this flaw to tr...
CVE-2019-10146
- EPSS 0.19%
- Veröffentlicht 18.03.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:30
A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page. An attacker could inject a specially crafted value that ...
CVE-2020-1720
- EPSS 0.35%
- Veröffentlicht 17.03.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:14
A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et...