CVE-2018-10756
- EPSS 2.38%
- Published 15.05.2020 16:15:11
- Last modified 21.11.2024 03:41:59
Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.
CVE-2020-3810
- EPSS 0.59%
- Published 15.05.2020 14:15:11
- Last modified 21.11.2024 05:31:47
Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files.
- EPSS 0.18%
- Published 14.05.2020 21:15:11
- Last modified 21.11.2024 04:52:53
In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploita...
CVE-2020-8020
- EPSS 0.22%
- Published 13.05.2020 15:15:11
- Last modified 21.11.2024 05:38:13
A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code to cause XSS. This issue affects: openSUSE open-build-service versions prior to 7cc32c8e2ff7290698e10...
CVE-2020-3327
- EPSS 14.14%
- Published 13.05.2020 03:15:11
- Last modified 21.11.2024 05:30:48
A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a heap bu...
CVE-2020-3341
- EPSS 5.71%
- Published 13.05.2020 03:15:11
- Last modified 21.11.2024 05:30:50
A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a...
CVE-2020-11058
- EPSS 0.12%
- Published 12.05.2020 21:15:11
- Last modified 21.11.2024 04:56:41
In FreeRDP after 1.1 and before 2.0.0, a stream out-of-bounds seek in rdp_read_font_capability_set could lead to a later out-of-bounds read. As a result, a manipulated client or server might force a disconnect due to an invalid data read. This has be...
CVE-2020-12823
- EPSS 1.51%
- Published 12.05.2020 18:15:13
- Last modified 21.11.2024 05:00:20
OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c.
- EPSS 0.06%
- Published 12.05.2020 18:15:13
- Last modified 21.11.2024 05:11:17
A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when the ldap_attr and ldap_e...
CVE-2020-8159
- EPSS 5.42%
- Published 12.05.2020 13:15:13
- Last modified 21.11.2024 05:38:24
There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view.