CVE-2020-6390
- EPSS 3.89%
- Veröffentlicht 11.02.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:37
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6385
- EPSS 1.4%
- Veröffentlicht 11.02.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:37
Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page.
CVE-2020-6382
- EPSS 2.9%
- Veröffentlicht 11.02.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:37
Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6381
- EPSS 2.9%
- Veröffentlicht 11.02.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:36
Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-15623
- EPSS 0.32%
- Veröffentlicht 04.02.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 04:29:09
Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.
CVE-2020-7106
- EPSS 4.09%
- Veröffentlicht 16.01.2020 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:36:38
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string fr...
CVE-2019-19925
- EPSS 9.23%
- Veröffentlicht 24.12.2019 17:15:10
- Zuletzt bearbeitet 21.11.2024 04:35:40
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
CVE-2019-19923
- EPSS 10.52%
- Veröffentlicht 24.12.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:40
flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).
CVE-2019-19926
- EPSS 8.34%
- Veröffentlicht 23.12.2019 01:15:13
- Zuletzt bearbeitet 21.11.2024 04:35:41
multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.
CVE-2019-19880
- EPSS 8.44%
- Veröffentlicht 18.12.2019 06:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:34
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.