CVE-2020-24654
- EPSS 0.84%
- Published 02.09.2020 17:15:12
- Last modified 21.11.2024 05:15:23
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
CVE-2020-15810
- EPSS 0.21%
- Published 02.09.2020 17:15:11
- Last modified 21.11.2024 05:06:13
An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggling attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser s...
CVE-2020-15811
- EPSS 0.25%
- Published 02.09.2020 17:15:11
- Last modified 21.11.2024 05:06:13
An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser s...
- EPSS 11.3%
- Published 31.08.2020 18:15:12
- Last modified 21.11.2024 05:03:05
An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_tok...
CVE-2020-25032
- EPSS 1.25%
- Published 31.08.2020 04:15:12
- Last modified 21.11.2024 05:16:42
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
CVE-2020-14352
- EPSS 4.04%
- Published 30.08.2020 15:15:12
- Last modified 21.11.2024 05:03:04
A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the...
CVE-2020-24972
- EPSS 20.71%
- Published 29.08.2020 21:15:11
- Last modified 21.11.2024 05:16:15
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line opti...
CVE-2020-24614
- EPSS 6.4%
- Published 25.08.2020 14:15:16
- Last modified 21.11.2024 05:15:09
Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.
CVE-2020-24606
- EPSS 6.34%
- Published 24.08.2020 18:15:10
- Last modified 21.11.2024 05:15:08
Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digest...
CVE-2020-14349
- EPSS 0.69%
- Published 24.08.2020 13:15:10
- Last modified 21.11.2024 05:03:04
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to exe...