CVE-2020-14155
- EPSS 0.15%
- Veröffentlicht 15.06.2020 17:15:10
- Zuletzt bearbeitet 21.11.2024 05:02:45
libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
CVE-2020-10757
- EPSS 0.41%
- Veröffentlicht 09.06.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 04:56:00
A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.
CVE-2020-13871
- EPSS 2.44%
- Veröffentlicht 06.06.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:02:02
SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.
CVE-2020-13817
- EPSS 0.38%
- Veröffentlicht 04.06.2020 13:15:11
- Zuletzt bearbeitet 05.05.2025 17:15:59
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated ...
CVE-2020-13645
- EPSS 0.61%
- Veröffentlicht 28.05.2020 12:15:11
- Zuletzt bearbeitet 21.11.2024 05:01:40
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended docu...
CVE-2020-13632
- EPSS 0.03%
- Veröffentlicht 27.05.2020 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:01:38
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
- EPSS 0.08%
- Veröffentlicht 27.05.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:38
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
CVE-2020-13631
- EPSS 0.09%
- Veröffentlicht 27.05.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:38
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
CVE-2020-7656
- EPSS 1.11%
- Veröffentlicht 19.05.2020 21:15:10
- Zuletzt bearbeitet 21.11.2024 05:37:33
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be...
CVE-2020-13143
- EPSS 2.98%
- Veröffentlicht 18.05.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:44
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753...