CVE-2020-6095
- EPSS 0.53%
- Veröffentlicht 27.03.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:35:05
An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send...
CVE-2020-1769
- EPSS 0.7%
- Veröffentlicht 27.03.2020 13:15:15
- Zuletzt bearbeitet 21.11.2024 05:11:21
In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be considered as security issue. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. ...
CVE-2020-1770
- EPSS 0.36%
- Veröffentlicht 27.03.2020 13:15:15
- Zuletzt bearbeitet 21.11.2024 05:11:21
Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
CVE-2020-1772
- EPSS 0.59%
- Veröffentlicht 27.03.2020 13:15:15
- Zuletzt bearbeitet 21.11.2024 05:11:21
It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and pri...
CVE-2020-10942
- EPSS 0.04%
- Veröffentlicht 24.03.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:25
In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.
CVE-2020-10938
- EPSS 1.68%
- Veröffentlicht 24.03.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:24
GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.
- EPSS 2.59%
- Veröffentlicht 24.03.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:17
A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that us...
CVE-2020-10593
- EPSS 1.22%
- Veröffentlicht 23.03.2020 13:15:13
- Zuletzt bearbeitet 21.11.2024 04:55:39
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aka TROVE-2020-004. This occurs in circpad_setup_machine_on_circ because a circuit-padding machine can be negoti...
CVE-2020-10592
- EPSS 2%
- Veröffentlicht 23.03.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:39
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002.
- EPSS 1.62%
- Veröffentlicht 22.03.2020 05:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:06
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSe...