CVE-2020-15169
- EPSS 1.25%
- Published 11.09.2020 16:15:12
- Last modified 21.11.2024 05:04:59
In Action View before versions 5.2.4.4 and 6.0.3.3 there is a potential Cross-Site Scripting (XSS) vulnerability in Action View's translation helpers. Views that allow the user to control the default (not found) value of the `t` and `translate` helpe...
CVE-2019-20917
- EPSS 0.67%
- Published 11.09.2020 05:15:12
- Last modified 21.11.2024 04:39:41
An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with the sqlauth or sqloper modules, this vulnerability ...
CVE-2020-25269
- EPSS 0.67%
- Published 11.09.2020 05:15:12
- Last modified 21.11.2024 05:17:49
An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0. The pgsql module contains a use after free vulnerability. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd ser...
CVE-2020-13920
- EPSS 0.15%
- Published 10.09.2020 19:15:13
- Last modified 21.11.2024 05:02:09
Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something ...
CVE-2020-6097
- EPSS 0.29%
- Published 10.09.2020 15:15:36
- Last modified 21.11.2024 05:35:05
An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denial-of-service. An attacker can ...
CVE-2020-25219
- EPSS 0.24%
- Published 09.09.2020 21:15:11
- Last modified 21.11.2024 05:17:41
url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.
CVE-2020-24379
- EPSS 1.11%
- Published 09.09.2020 19:15:21
- Last modified 21.11.2024 05:14:42
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
- EPSS 44.38%
- Published 09.09.2020 19:15:21
- Last modified 21.11.2024 05:16:12
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
CVE-2020-7068
- EPSS 1.16%
- Published 09.09.2020 18:15:23
- Last modified 21.11.2024 05:36:36
In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.
- EPSS 0.04%
- Published 09.09.2020 16:15:12
- Last modified 21.11.2024 05:17:39
In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctnetlink_parse_tuple_filter in net/netfilter/nf_connt...