CVE-2020-15466
- EPSS 0.63%
- Veröffentlicht 05.07.2020 11:15:09
- Zuletzt bearbeitet 21.11.2024 05:05:33
In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that an offset increases in all situations.
CVE-2020-15396
- EPSS 0.07%
- Veröffentlicht 30.06.2020 12:15:12
- Zuletzt bearbeitet 21.11.2024 05:05:29
In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.
CVE-2017-18922
- EPSS 4.78%
- Veröffentlicht 30.06.2020 11:15:10
- Zuletzt bearbeitet 21.11.2024 03:21:16
It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overf...
CVE-2020-15393
- EPSS 0.09%
- Veröffentlicht 29.06.2020 22:15:10
- Zuletzt bearbeitet 21.11.2024 05:05:28
In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory leak, aka CID-28ebeb8db770.
CVE-2020-4067
- EPSS 1.1%
- Veröffentlicht 29.06.2020 20:15:10
- Zuletzt bearbeitet 21.11.2024 05:32:14
In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use their connection to intelligent...
CVE-2020-8014
- EPSS 0.03%
- Veröffentlicht 29.06.2020 12:15:10
- Zuletzt bearbeitet 21.11.2024 05:38:13
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local attackers with the privileges of the kopano user to escalate to root. This issue affects: openSUSE Leap 1...
CVE-2020-8022
- EPSS 0.19%
- Veröffentlicht 29.06.2020 09:15:11
- Zuletzt bearbeitet 21.11.2024 05:38:14
A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux Enterprise S...
CVE-2020-11996
- EPSS 37.12%
- Veröffentlicht 26.06.2020 17:15:10
- Zuletzt bearbeitet 21.11.2024 04:59:04
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTT...
CVE-2020-10769
- EPSS 0.08%
- Veröffentlicht 26.06.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:01
A buffer over-read flaw was found in RH kernel versions before 5.0 in crypto_authenc_extractkeys in crypto/authenc.c in the IPsec Cryptographic algorithm's module, authenc. When a payload longer than 4 bytes, and is not following 4-byte alignment bou...
CVE-2020-10753
- EPSS 0.34%
- Veröffentlicht 26.06.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:59
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file genera...