CVE-2020-35605
- EPSS 5.52%
- Published 21.12.2020 20:15:12
- Last modified 24.04.2025 17:39:27
The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message.
CVE-2020-35573
- EPSS 1.71%
- Published 20.12.2020 05:15:09
- Last modified 21.11.2024 05:27:36
srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timestamp tag in an SRS address.
CVE-2020-35475
- EPSS 0.59%
- Published 18.12.2020 08:15:15
- Last modified 21.11.2024 05:27:22
In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to change all userrights, and the table on the left side...
CVE-2020-35477
- EPSS 0.55%
- Published 18.12.2020 08:15:15
- Last modified 21.11.2024 05:27:22
MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpage to Special:MyLanguage/Main Page, visits a log entry on Special:Log, and toggles the "Change visibility of selected log entries" ...
CVE-2020-35479
- EPSS 0.86%
- Published 18.12.2020 08:15:15
- Last modified 21.11.2024 05:27:22
MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, the return of Language::userTimeAndDate is is always unsafe for HTML in a month value. This affects Me...
CVE-2020-35480
- EPSS 0.34%
- Published 18.12.2020 08:15:15
- Last modified 21.11.2024 05:27:22
An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently, exposing s...
CVE-2020-35490
- EPSS 5.58%
- Published 17.12.2020 19:15:14
- Last modified 21.11.2024 05:27:24
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.
CVE-2020-35491
- EPSS 8.06%
- Published 17.12.2020 19:15:14
- Last modified 21.11.2024 05:27:24
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.
CVE-2020-29361
- EPSS 0.25%
- Published 16.12.2020 14:15:12
- Last modified 21.11.2024 05:23:54
An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or callo...
CVE-2020-29363
- EPSS 0.58%
- Published 16.12.2020 14:15:12
- Last modified 21.11.2024 05:23:54
An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in ...