CVE-2020-11061
- EPSS 0.91%
- Published 10.07.2020 20:15:11
- Last modified 21.11.2024 04:56:42
In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mi...
CVE-2020-10756
- EPSS 0.03%
- Published 09.07.2020 16:15:13
- Last modified 21.11.2024 04:56:00
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious...
CVE-2020-12399
- EPSS 0.1%
- Published 09.07.2020 15:15:10
- Last modified 21.11.2024 04:59:38
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
CVE-2020-12402
- EPSS 0.1%
- Published 09.07.2020 15:15:10
- Last modified 21.11.2024 04:59:38
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to re...
CVE-2020-10745
- EPSS 16.33%
- Published 07.07.2020 14:15:11
- Last modified 21.11.2024 04:55:58
A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows a remote attacker could to cause the Samba server to consume excessive CPU use, resulting in a denia...
CVE-2020-10730
- EPSS 2.76%
- Published 07.07.2020 14:15:10
- Last modified 21.11.2024 04:55:56
A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17, before 4.11.11 and before 4.12.4. Although some versions of Samba shipped with Red Hat Enterprise Linux do not support Samba in ...
CVE-2020-15564
- EPSS 0.08%
- Published 07.07.2020 13:15:10
- Last modified 21.11.2024 05:05:44
An issue was discovered in Xen through 4.13.x, allowing Arm guest OS users to cause a hypervisor crash because of a missing alignment check in VCPUOP_register_vcpu_info. The hypercall VCPUOP_register_vcpu_info is used by a guest to register a shared ...
CVE-2020-15565
- EPSS 0.08%
- Published 07.07.2020 13:15:10
- Last modified 21.11.2024 05:05:45
An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of service or possibly gain privileges because of insufficient cache write-back under VT-d. When page tables are shared between IOMMU and C...
CVE-2020-15566
- EPSS 0.06%
- Published 07.07.2020 13:15:10
- Last modified 21.11.2024 05:05:45
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a host OS crash because of incorrect error handling in event-channel port allocation. The allocation of an event-channel port may fail for multiple reasons: (1) port is a...
CVE-2020-15567
- EPSS 0.06%
- Published 07.07.2020 13:15:10
- Last modified 21.11.2024 05:05:45
An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic modification of a live EPT PTE. When mapping guest EPT (nested paging) tables, Xen would in some circum...