CVE-2020-14782
- EPSS 0.14%
- Published 21.10.2020 15:15:18
- Last modified 27.05.2025 16:40:51
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthe...
CVE-2020-8758
- EPSS 1.59%
- Published 10.09.2020 15:16:53
- Last modified 21.11.2024 05:39:23
Improper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, 11.12.79, 11.22.79, 12.0.68 and 14.0.39 may allow an unauthenticated user to potentially enable escalation of privilege via networ...
CVE-2020-8620
- EPSS 7.29%
- Published 21.08.2020 21:15:12
- Last modified 21.11.2024 05:39:08
In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.
CVE-2020-8621
- EPSS 4.22%
- Published 21.08.2020 21:15:12
- Last modified 21.11.2024 05:39:08
In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that ...
CVE-2020-8622
- EPSS 0.6%
- Published 21.08.2020 21:15:12
- Last modified 21.11.2024 05:39:08
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed re...
CVE-2020-8623
- EPSS 5.63%
- Published 21.08.2020 21:15:12
- Last modified 21.11.2024 05:39:08
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To ...
CVE-2020-8624
- EPSS 1.95%
- Published 21.08.2020 21:15:12
- Last modified 21.11.2024 05:39:08
In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privileges to ch...
CVE-2020-16166
- EPSS 1.85%
- Published 30.07.2020 21:15:11
- Last modified 21.11.2024 05:06:53
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c...
CVE-2020-15778
- EPSS 61.48%
- Published 24.07.2020 14:15:12
- Last modified 28.07.2025 18:12:45
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous arg...
CVE-2020-15852
- EPSS 0.16%
- Published 20.07.2020 19:15:11
- Last modified 21.11.2024 05:06:18
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes ...