CVE-2020-14779
- EPSS 0.2%
- Published 21.10.2020 15:15:18
- Last modified 27.05.2025 16:42:14
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows una...
CVE-2020-14781
- EPSS 0.1%
- Published 21.10.2020 15:15:18
- Last modified 27.05.2025 16:41:52
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JNDI). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthentica...
CVE-2020-15862
- EPSS 0.06%
- Published 20.08.2020 01:17:13
- Last modified 21.11.2024 05:06:19
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
CVE-2020-14356
- EPSS 0.93%
- Published 19.08.2020 15:15:12
- Last modified 21.11.2024 05:03:05
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
CVE-2020-16166
- EPSS 1.85%
- Published 30.07.2020 21:15:11
- Last modified 21.11.2024 05:06:53
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c...
CVE-2020-15778
- EPSS 61.48%
- Published 24.07.2020 14:15:12
- Last modified 28.07.2025 18:12:45
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous arg...
CVE-2020-14145
- EPSS 1.25%
- Published 29.06.2020 18:15:11
- Last modified 21.11.2024 05:02:44
The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has ...
CVE-2020-10732
- EPSS 0.05%
- Published 12.06.2020 14:15:11
- Last modified 21.11.2024 04:55:57
A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data.
CVE-2020-13817
- EPSS 0.38%
- Published 04.06.2020 13:15:11
- Last modified 05.05.2025 17:15:59
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated ...
CVE-2020-13143
- EPSS 2.98%
- Published 18.05.2020 18:15:11
- Last modified 21.11.2024 05:00:44
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753...