CVE-2020-12402
- EPSS 0.08%
- Veröffentlicht 09.07.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:59:38
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to re...
CVE-2020-12424
- EPSS 0.16%
- Veröffentlicht 09.07.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:59:42
When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of an origin that was previously granted permission; bypassing the prompt. This vulnerability affects F...
CVE-2020-15095
- EPSS 0.04%
- Veröffentlicht 07.07.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:04:47
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and...
CVE-2020-10745
- EPSS 16.33%
- Veröffentlicht 07.07.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:58
A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows a remote attacker could to cause the Samba server to consume excessive CPU use, resulting in a denia...
CVE-2020-10730
- EPSS 2.76%
- Veröffentlicht 07.07.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:55:56
A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17, before 4.11.11 and before 4.12.4. Although some versions of Samba shipped with Red Hat Enterprise Linux do not support Samba in ...
CVE-2020-15565
- EPSS 0.08%
- Veröffentlicht 07.07.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 05:05:45
An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of service or possibly gain privileges because of insufficient cache write-back under VT-d. When page tables are shared between IOMMU and C...
CVE-2020-15567
- EPSS 0.06%
- Veröffentlicht 07.07.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 05:05:45
An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic modification of a live EPT PTE. When mapping guest EPT (nested paging) tables, Xen would in some circum...
CVE-2020-15563
- EPSS 0.08%
- Veröffentlicht 07.07.2020 13:15:09
- Zuletzt bearbeitet 21.11.2024 05:05:44
An issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS users to cause a hypervisor crash. An inverted conditional in x86 HVM guests' dirty video RAM tracking code allows such guests to make Xen de-reference a pointer guaranteed to p...
CVE-2020-10760
- EPSS 2.55%
- Veröffentlicht 06.07.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:00
A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samba LDAP user could use this flaw to crash samba.
CVE-2020-14303
- EPSS 26.12%
- Veröffentlicht 06.07.2020 18:15:20
- Zuletzt bearbeitet 21.11.2024 05:02:57
A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash.