CVE-2020-11984
- EPSS 76.31%
- Published 07.08.2020 16:15:11
- Last modified 21.11.2024 04:59:02
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
CVE-2020-11993
- EPSS 38.85%
- Published 07.08.2020 16:15:11
- Last modified 01.05.2025 15:40:19
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLev...
CVE-2019-20907
- EPSS 0.29%
- Published 13.07.2020 13:15:10
- Last modified 21.11.2024 04:39:39
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
CVE-2019-20892
- EPSS 0.54%
- Published 25.06.2020 10:15:10
- Last modified 21.11.2024 04:39:37
net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream...
CVE-2020-15025
- EPSS 1.89%
- Published 24.06.2020 19:15:10
- Last modified 21.11.2024 05:04:38
ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC alg...
CVE-2020-13871
- EPSS 2.44%
- Published 06.06.2020 16:15:10
- Last modified 21.11.2024 05:02:02
SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.
CVE-2020-13254
- EPSS 8.67%
- Published 03.06.2020 14:15:12
- Last modified 21.11.2024 05:00:53
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.
CVE-2020-13596
- EPSS 0.99%
- Published 03.06.2020 14:15:12
- Last modified 21.11.2024 05:01:34
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.
CVE-2020-13632
- EPSS 0.03%
- Published 27.05.2020 15:15:13
- Last modified 21.11.2024 05:01:38
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
- EPSS 0.08%
- Published 27.05.2020 15:15:12
- Last modified 21.11.2024 05:01:38
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.