CVE-2020-14004
- EPSS 0.2%
- Published 12.06.2020 16:15:10
- Last modified 21.11.2024 05:02:19
An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an unprivileged user by default. If /run/icinga2/cmd is...
CVE-2020-13696
- EPSS 0.04%
- Published 08.06.2020 17:15:10
- Last modified 21.11.2024 05:01:45
An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local attacker wi...
CVE-2020-6494
- EPSS 0.5%
- Published 03.06.2020 23:15:11
- Last modified 21.11.2024 05:35:50
Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2020-6496
- EPSS 1.34%
- Published 03.06.2020 23:15:11
- Last modified 21.11.2024 05:35:50
Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVE-2020-13379
- EPSS 92.95%
- Published 03.06.2020 19:15:10
- Last modified 21.11.2024 05:01:08
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can b...
CVE-2020-13614
- EPSS 0.58%
- Published 26.05.2020 23:15:10
- Last modified 21.11.2024 05:01:36
An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.
CVE-2020-6487
- EPSS 0.69%
- Published 21.05.2020 04:15:14
- Last modified 21.11.2024 05:35:49
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVE-2020-6488
- EPSS 0.61%
- Published 21.05.2020 04:15:14
- Last modified 21.11.2024 05:35:49
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVE-2020-6489
- EPSS 1.04%
- Published 21.05.2020 04:15:14
- Last modified 21.11.2024 05:35:49
Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced the user to take certain actions in developer tools to obtain potentially sensitive information from disk via a crafted...
CVE-2020-6490
- EPSS 1.04%
- Published 21.05.2020 04:15:14
- Last modified 21.11.2024 05:35:49
Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page.