CVE-2020-10713
- EPSS 0.26%
- Published 30.07.2020 13:15:10
- Last modified 21.11.2024 04:55:54
A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure Boot protections. In order to load an untrusted or modified kernel, a...
CVE-2020-16135
- EPSS 1.41%
- Published 29.07.2020 21:15:13
- Last modified 21.11.2024 05:06:49
libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.
CVE-2020-15705
- EPSS 0.03%
- Published 29.07.2020 18:15:14
- Last modified 21.11.2024 05:06:03
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB imag...
CVE-2020-15706
- EPSS 0.06%
- Published 29.07.2020 18:15:14
- Last modified 21.11.2024 05:06:03
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure b...
CVE-2020-15707
- EPSS 0.04%
- Published 29.07.2020 18:15:14
- Last modified 21.11.2024 05:06:04
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffe...
CVE-2020-16117
- EPSS 0.45%
- Published 29.07.2020 18:15:14
- Last modified 21.11.2024 05:06:47
In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related to imapx_free_capability and im...
CVE-2020-15863
- EPSS 0.05%
- Published 28.07.2020 16:15:12
- Last modified 21.11.2024 05:06:20
hw/net/xgmac.c in the XGMAC Ethernet controller in QEMU before 07-20-2020 has a buffer overflow. This occurs during packet transmission and affects the highbank and midway emulated machines. A guest user or process could use this flaw to crash the QE...
CVE-2020-12460
- EPSS 14.59%
- Published 27.07.2020 23:15:12
- Last modified 21.11.2024 04:59:44
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a specially crafted DMARC aggregate report. This can cau...
CVE-2020-15103
- EPSS 0.28%
- Published 27.07.2020 18:15:13
- Last modified 21.11.2024 05:04:48
In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not checked against local surface coordinates and blindl...
CVE-2020-15954
- EPSS 0.14%
- Published 27.07.2020 07:15:11
- Last modified 21.11.2024 05:06:31
KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.