CVE-2020-10663
- EPSS 6.54%
- Published 28.04.2020 21:15:11
- Last modified 21.11.2024 04:55:47
The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavi...
CVE-2020-12243
- EPSS 6.57%
- Published 28.04.2020 19:15:12
- Last modified 21.11.2024 04:59:22
In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
CVE-2020-12268
- EPSS 0.81%
- Published 27.04.2020 02:15:12
- Last modified 21.11.2024 04:59:24
jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow.
CVE-2020-12137
- EPSS 0.95%
- Published 24.04.2020 13:15:11
- Last modified 21.11.2024 04:59:19
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, ...
CVE-2020-12105
- EPSS 0.17%
- Published 23.04.2020 17:15:12
- Last modified 21.11.2024 04:59:15
OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers in performing man-in-the-middle attacks.
CVE-2020-11945
- EPSS 28.48%
- Published 23.04.2020 15:15:14
- Last modified 21.11.2024 04:58:57
An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a s...
CVE-2020-1983
- EPSS 0.19%
- Published 22.04.2020 20:15:11
- Last modified 21.11.2024 05:11:47
A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.
CVE-2019-20787
- EPSS 0.68%
- Published 22.04.2020 17:15:12
- Last modified 21.11.2024 04:39:21
Teeworlds before 0.7.4 has an integer overflow when computing a tilemap size.
CVE-2020-12066
- EPSS 5.73%
- Published 22.04.2020 17:15:12
- Last modified 21.11.2024 04:59:12
CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
CVE-2020-1967
- EPSS 66.69%
- Published 21.04.2020 14:15:11
- Last modified 21.11.2024 05:11:45
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occur...