CVE-2020-12625
- EPSS 4.16%
- Veröffentlicht 04.05.2020 02:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:56
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.
- EPSS 0.09%
- Veröffentlicht 30.04.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:59:10
SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a /tmp/sqliteodbc$$ file with new contents that cause loading of an arbitrary library.
CVE-2020-12137
- EPSS 0.95%
- Veröffentlicht 24.04.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:19
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, ...
CVE-2020-12066
- EPSS 5.73%
- Veröffentlicht 22.04.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:59:12
CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
CVE-2020-6436
- EPSS 1.49%
- Veröffentlicht 13.04.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:43
Use after free in window management in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6438
- EPSS 0.69%
- Veröffentlicht 13.04.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:43
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extens...
CVE-2020-6444
- EPSS 1.39%
- Veröffentlicht 13.04.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:44
Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6447
- EPSS 1.49%
- Veröffentlicht 13.04.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:44
Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6448
- EPSS 1.49%
- Veröffentlicht 13.04.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:44
Use after free in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6450
- EPSS 0.8%
- Veröffentlicht 13.04.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:45
Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.