CVE-2020-11023
- EPSS 83.83%
- Veröffentlicht 29.04.2020 21:15:11
- Zuletzt bearbeitet 07.11.2025 19:32:52
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may ex...
CVE-2020-12465
- EPSS 0.38%
- Veröffentlicht 29.04.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:59:45
An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10, aka CID-b102f0c522cf. An oversized packet with too many rx fragments can corrupt memory of adjacent pages.
CVE-2020-12464
- EPSS 0.8%
- Veröffentlicht 29.04.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 04:59:45
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925.
- EPSS 0.4%
- Veröffentlicht 29.04.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:58:49
In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a concurrent page table upgrade...
CVE-2020-12243
- EPSS 4.42%
- Veröffentlicht 28.04.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:59:22
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
CVE-2020-5867
- EPSS 0.4%
- Veröffentlicht 23.04.2020 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:34:43
In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check and install packages
CVE-2020-5865
- EPSS 0.39%
- Veröffentlicht 23.04.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:34:43
In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks.
CVE-2020-2816
- EPSS 2.7%
- Veröffentlicht 15.04.2020 14:15:29
- Zuletzt bearbeitet 21.11.2024 05:26:21
Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Ja...
CVE-2020-2830
- EPSS 4.95%
- Veröffentlicht 15.04.2020 14:15:29
- Zuletzt bearbeitet 21.11.2024 05:26:23
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthe...
CVE-2020-2800
- EPSS 2.88%
- Veröffentlicht 15.04.2020 14:15:28
- Zuletzt bearbeitet 21.11.2024 05:26:18
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability ...