CVE-2018-10756
- EPSS 2.38%
- Veröffentlicht 15.05.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 03:41:59
Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.
CVE-2020-3810
- EPSS 0.59%
- Veröffentlicht 15.05.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:31:47
Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files.
- EPSS 0.18%
- Veröffentlicht 14.05.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:52:53
In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploita...
CVE-2020-8020
- EPSS 0.22%
- Veröffentlicht 13.05.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:38:13
A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code to cause XSS. This issue affects: openSUSE open-build-service versions prior to 7cc32c8e2ff7290698e10...
CVE-2020-3327
- EPSS 14.14%
- Veröffentlicht 13.05.2020 03:15:11
- Zuletzt bearbeitet 21.11.2024 05:30:48
A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a heap bu...
CVE-2020-3341
- EPSS 5.71%
- Veröffentlicht 13.05.2020 03:15:11
- Zuletzt bearbeitet 21.11.2024 05:30:50
A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a...
CVE-2020-11058
- EPSS 0.12%
- Veröffentlicht 12.05.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:41
In FreeRDP after 1.1 and before 2.0.0, a stream out-of-bounds seek in rdp_read_font_capability_set could lead to a later out-of-bounds read. As a result, a manipulated client or server might force a disconnect due to an invalid data read. This has be...
CVE-2020-12823
- EPSS 1.51%
- Veröffentlicht 12.05.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:00:20
OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c.
- EPSS 0.06%
- Veröffentlicht 12.05.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:17
A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when the ldap_attr and ldap_e...
CVE-2020-8159
- EPSS 5.42%
- Veröffentlicht 12.05.2020 13:15:13
- Zuletzt bearbeitet 21.11.2024 05:38:24
There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view.