- EPSS 11.3%
- Published 31.08.2020 18:15:12
- Last modified 21.11.2024 05:03:05
An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_tok...
CVE-2020-12829
- EPSS 0.11%
- Published 31.08.2020 15:15:10
- Last modified 21.11.2024 05:00:21
In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback. A local attacker could abuse t...
CVE-2020-25032
- EPSS 1.25%
- Published 31.08.2020 04:15:12
- Last modified 21.11.2024 05:16:42
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
CVE-2020-8244
- EPSS 0.37%
- Published 30.08.2020 15:15:12
- Last modified 21.11.2024 05:38:34
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, ...
CVE-2019-14904
- EPSS 0.04%
- Published 26.08.2020 03:15:11
- Last modified 21.11.2024 04:27:39
A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the remote machine. An attacker coul...
CVE-2020-24616
- EPSS 3.59%
- Published 25.08.2020 18:15:11
- Last modified 21.11.2024 05:15:09
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
CVE-2020-24606
- EPSS 6.34%
- Published 24.08.2020 18:15:10
- Last modified 21.11.2024 05:15:08
Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digest...
CVE-2020-14350
- EPSS 0.03%
- Published 24.08.2020 13:15:10
- Last modified 21.11.2024 05:03:04
It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the insta...
CVE-2020-8622
- EPSS 0.6%
- Published 21.08.2020 21:15:12
- Last modified 21.11.2024 05:39:08
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed re...
CVE-2020-8623
- EPSS 5.63%
- Published 21.08.2020 21:15:12
- Last modified 21.11.2024 05:39:08
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To ...