CVE-2019-20446
- EPSS 0.97%
- Veröffentlicht 02.02.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:38:30
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows expon...
CVE-2020-8492
- EPSS 3.25%
- Veröffentlicht 30.01.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:56
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicA...
CVE-2019-20444
- EPSS 4.17%
- Veröffentlicht 29.01.2020 21:15:11
- Zuletzt bearbeitet 01.07.2025 18:15:23
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."
CVE-2019-20445
- EPSS 0.96%
- Veröffentlicht 29.01.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:38:30
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
CVE-2019-18634
- EPSS 87.27%
- Veröffentlicht 29.01.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:33:25
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however, it is NOT the default for upst...
- EPSS 93.98%
- Veröffentlicht 29.01.2020 16:15:12
- Zuletzt bearbeitet 22.10.2025 00:17:11
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This ...
CVE-2015-8011
- EPSS 4.15%
- Veröffentlicht 28.01.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 02:37:50
Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and ...
CVE-2020-8112
- EPSS 1.43%
- Veröffentlicht 28.01.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:38:19
opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.
CVE-2020-8086
- EPSS 0.67%
- Veröffentlicht 28.01.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:16
The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches the username ...
CVE-2020-0549
- EPSS 0.12%
- Veröffentlicht 28.01.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 04:53:43
Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.