CVE-2020-13397
- EPSS 0.08%
- Published 22.05.2020 18:15:11
- Last modified 21.11.2024 05:01:10
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in security_fips_decrypt in libfreerdp/core/security.c due to an uninitialized value.
CVE-2020-13398
- EPSS 0.5%
- Published 22.05.2020 18:15:11
- Last modified 21.11.2024 05:01:10
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.
CVE-2020-10711
- EPSS 3.51%
- Published 22.05.2020 15:15:11
- Last modified 21.11.2024 04:55:54
A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the...
CVE-2020-11076
- EPSS 1.78%
- Published 22.05.2020 15:15:11
- Last modified 21.11.2024 04:56:44
In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.
CVE-2020-11077
- EPSS 0.82%
- Published 22.05.2020 15:15:11
- Last modified 21.11.2024 04:56:44
In Puma (RubyGem) before 4.3.5 and 3.12.6, a client could smuggle a request through a proxy, causing the proxy to send a response back to another unknown client. If the proxy uses persistent connections and the client adds another request in via HTTP...
CVE-2020-12693
- EPSS 0.19%
- Published 21.05.2020 23:15:11
- Last modified 21.11.2024 05:00:05
Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A race condition allows a user to launch a process as an arbitrary user.
CVE-2020-13113
- EPSS 0.7%
- Published 21.05.2020 17:15:10
- Last modified 21.11.2024 05:00:40
An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions.
CVE-2020-13112
- EPSS 0.97%
- Published 21.05.2020 16:15:10
- Last modified 21.11.2024 05:00:40
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
CVE-2020-6487
- EPSS 0.69%
- Published 21.05.2020 04:15:14
- Last modified 21.11.2024 05:35:49
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVE-2020-6488
- EPSS 0.61%
- Published 21.05.2020 04:15:14
- Last modified 21.11.2024 05:35:49
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.