CVE-2020-14350
- EPSS 0.03%
- Published 24.08.2020 13:15:10
- Last modified 21.11.2024 05:03:04
It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the insta...
CVE-2020-8620
- EPSS 7.29%
- Published 21.08.2020 21:15:12
- Last modified 21.11.2024 05:39:08
In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.
CVE-2020-8621
- EPSS 4.22%
- Published 21.08.2020 21:15:12
- Last modified 21.11.2024 05:39:08
In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that ...
CVE-2020-8622
- EPSS 0.6%
- Published 21.08.2020 21:15:12
- Last modified 21.11.2024 05:39:08
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed re...
CVE-2020-8623
- EPSS 5.63%
- Published 21.08.2020 21:15:12
- Last modified 21.11.2024 05:39:08
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To ...
CVE-2020-8624
- EPSS 1.95%
- Published 21.08.2020 21:15:12
- Last modified 21.11.2024 05:39:08
In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privileges to ch...
CVE-2020-14356
- EPSS 0.93%
- Published 19.08.2020 15:15:12
- Last modified 21.11.2024 05:03:05
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
CVE-2020-24394
- EPSS 0.02%
- Published 19.08.2020 13:15:10
- Last modified 21.11.2024 05:14:44
In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs because the current umask is not considered.
CVE-2020-1472
- EPSS 94.43%
- Published 17.08.2020 19:15:15
- Last modified 07.03.2025 14:57:32
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability...
- EPSS 14.29%
- Published 17.08.2020 16:15:13
- Last modified 21.11.2024 05:38:33
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.