CVE-2020-24386
- EPSS 0.63%
- Published 04.01.2021 17:15:13
- Last modified 21.11.2024 05:14:43
An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).
CVE-2020-25275
- EPSS 6.85%
- Published 04.01.2021 17:15:13
- Last modified 21.11.2024 05:17:50
Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.
CVE-2020-35965
- EPSS 0.39%
- Published 04.01.2021 02:15:11
- Last modified 21.11.2024 05:28:36
decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations.
CVE-2020-12658
- EPSS 0.57%
- Published 31.12.2020 01:15:12
- Last modified 21.11.2024 05:00:00
gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We are already on a shutdown path when running the code in question, so a DoS there doesn't ma...
CVE-2019-15523
- EPSS 0.67%
- Published 30.12.2020 21:15:12
- Last modified 21.11.2024 04:28:55
An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglects to call this function again, as required by the design of the API.
CVE-2020-26247
- EPSS 1.79%
- Published 30.12.2020 19:15:12
- Last modified 21.11.2024 05:19:38
Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing ...
CVE-2020-35730
- EPSS 64.25%
- Published 28.12.2020 20:15:13
- Last modified 22.10.2025 00:17:06
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcu...
CVE-2020-35738
- EPSS 0.41%
- Published 28.12.2020 04:15:12
- Last modified 21.11.2024 05:27:59
WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.
CVE-2020-35728
- EPSS 41.43%
- Published 27.12.2020 05:15:11
- Last modified 27.08.2025 21:15:36
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.js...
- EPSS 1.62%
- Published 24.12.2020 15:15:12
- Last modified 21.11.2024 05:22:25
The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM.