CVE-2020-6467
- EPSS 2.05%
- Published 21.05.2020 04:15:11
- Last modified 21.11.2024 05:35:47
Use after free in WebRTC in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6468
- EPSS 42.47%
- Published 21.05.2020 04:15:11
- Last modified 21.11.2024 05:35:47
Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6469
- EPSS 0.7%
- Published 21.05.2020 04:15:11
- Last modified 21.11.2024 05:35:47
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
CVE-2020-6470
- EPSS 1.16%
- Published 21.05.2020 04:15:11
- Last modified 21.11.2024 05:35:47
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 83.0.4103.61 allowed a local attacker to inject arbitrary scripts or HTML (UXSS) via crafted clipboard contents.
CVE-2020-10995
- EPSS 0.09%
- Published 19.05.2020 17:15:10
- Last modified 21.11.2024 04:56:32
PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the DNS protocol has been found that allow malicious parties to use recursive DNS services to attack third party authoritat...
CVE-2020-12244
- EPSS 0.09%
- Published 19.05.2020 14:15:11
- Last modified 21.11.2024 04:59:22
An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated in SyncRes::processAnswer, allowing an attacker to bypass DNSSEC validation.
CVE-2020-12108
- EPSS 5.59%
- Published 06.05.2020 15:15:11
- Last modified 21.11.2024 04:59:15
/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
CVE-2020-12672
- EPSS 0.36%
- Published 06.05.2020 03:15:11
- Last modified 21.11.2024 05:00:02
GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.
CVE-2020-12640
- EPSS 20.08%
- Published 04.05.2020 15:15:14
- Last modified 21.11.2024 04:59:57
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.
CVE-2020-12641
- EPSS 93.07%
- Published 04.05.2020 15:15:14
- Last modified 14.03.2025 17:19:14
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.