CVE-2020-10781
- EPSS 0.1%
- Published 16.09.2020 13:15:10
- Last modified 21.11.2024 04:56:03
A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the ability to read the /sys/class/zram-control/hot_add file can create ZRAM device nodes in the /dev/ directory. This read allocates...
CVE-2020-14385
- EPSS 0.04%
- Published 15.09.2020 22:15:13
- Last modified 21.11.2024 05:03:08
A flaw was found in the Linux kernel before 5.9-rc4. A failure of the file system metadata validator in XFS can cause an inode with a valid, user-creatable extended attribute to be flagged as corrupt. This can lead to the filesystem being shutdown, o...
CVE-2020-14314
- EPSS 0.01%
- Published 15.09.2020 20:15:13
- Last modified 21.11.2024 05:02:59
A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a directory with broken indexing. This flaw allows a local user to crash the system if the directory exists. The high...
CVE-2020-8927
- EPSS 0.39%
- Published 15.09.2020 10:15:12
- Last modified 21.11.2024 05:39:41
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 ...
CVE-2020-24660
- EPSS 0.68%
- Published 14.09.2020 13:15:10
- Last modified 21.11.2024 05:15:27
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG h...
CVE-2020-25284
- EPSS 0.08%
- Published 13.09.2020 18:15:09
- Last modified 21.11.2024 05:17:51
The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map or unmap rbd block devices, aka CID-f44d04e696fe.
CVE-2020-25285
- EPSS 0.09%
- Published 13.09.2020 18:15:09
- Last modified 21.11.2024 05:17:51
A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local attackers to corrupt memory, cause a NULL pointer dereference, or possibly have unspecified other impact, aka CID-17743798d812.
CVE-2020-14330
- EPSS 0.12%
- Published 11.09.2020 18:15:13
- Last modified 21.11.2024 05:03:01
An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to read keys use...
CVE-2020-14332
- EPSS 0.14%
- Published 11.09.2020 18:15:13
- Last modified 21.11.2024 05:03:01
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The highest threa...
CVE-2020-15166
- EPSS 0.3%
- Published 11.09.2020 16:15:12
- Last modified 21.11.2024 05:04:59
In ZeroMQ before version 4.3.3, there is a denial-of-service vulnerability. Users with TCP transport public endpoints, even with CURVE/ZAP enabled, are impacted. If a raw TCP socket is opened and connected to an endpoint that is fully configured with...