CVE-2021-45082
- EPSS 0.04%
- Veröffentlicht 19.02.2022 00:15:17
- Zuletzt bearbeitet 21.11.2024 06:31:54
An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)
CVE-2021-46142
- EPSS 0.09%
- Veröffentlicht 06.01.2022 04:15:06
- Zuletzt bearbeitet 21.11.2024 06:33:40
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
CVE-2021-46141
- EPSS 0.09%
- Veröffentlicht 06.01.2022 04:15:06
- Zuletzt bearbeitet 21.11.2024 06:33:40
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
CVE-2020-15803
- EPSS 2.09%
- Veröffentlicht 17.07.2020 03:15:11
- Zuletzt bearbeitet 21.11.2024 05:06:12
Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.
CVE-2020-14983
- EPSS 0.68%
- Veröffentlicht 22.06.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:04:34
The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading to a buffer overflow. A malicious user can overwrite the server's stack.
CVE-2020-6495
- EPSS 0.52%
- Veröffentlicht 03.06.2020 23:15:11
- Zuletzt bearbeitet 21.11.2024 05:35:50
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
CVE-2020-6493
- EPSS 3.61%
- Veröffentlicht 03.06.2020 23:15:11
- Zuletzt bearbeitet 21.11.2024 05:35:50
Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVE-2020-6456
- EPSS 0.61%
- Veröffentlicht 13.04.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:35:45
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker to bypass site isolation via crafted clipboard contents.
CVE-2020-6455
- EPSS 1.24%
- Veröffentlicht 13.04.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:35:45
Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6445
- EPSS 0.53%
- Veröffentlicht 13.04.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:44
Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.