CVE-2020-5247
- EPSS 3.07%
 - Published 28.02.2020 17:15:12
 - Last modified 21.11.2024 05:33:45
 
In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response header, an attacker can use newline characters (i.e. `CR`, `LF` or`/r`, `/n`) to end the header and inject malicious content, such as ...
CVE-2019-10064
- EPSS 1.41%
 - Published 28.02.2020 15:15:11
 - Last modified 21.11.2024 04:18:19
 
hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, which results in inappropriate use of deterministic values. This was fixed in conjunction with CVE-201...
CVE-2020-9431
- EPSS 4.4%
 - Published 27.02.2020 23:15:13
 - Last modified 21.11.2024 05:40:37
 
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addressed in epan/dissectors/packet-lte-rrc.c by adjusting certain append operations.
CVE-2020-6383
- EPSS 15.47%
 - Published 27.02.2020 23:15:12
 - Last modified 21.11.2024 05:35:37
 
Type confusion in V8 in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6384
- EPSS 0.81%
 - Published 27.02.2020 23:15:12
 - Last modified 21.11.2024 05:35:37
 
Use after free in WebAudio in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6386
- EPSS 0.84%
 - Published 27.02.2020 23:15:12
 - Last modified 21.11.2024 05:35:37
 
Use after free in speech in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6418
- EPSS 88.74%
 - Published 27.02.2020 23:15:12
 - Last modified 24.10.2025 21:04:01
 
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-9428
- EPSS 8.18%
 - Published 27.02.2020 23:15:12
 - Last modified 21.11.2024 05:40:37
 
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c by using more careful sscanf parsing.
CVE-2020-9430
- EPSS 3.61%
 - Published 27.02.2020 23:15:12
 - Last modified 21.11.2024 05:40:37
 
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addressed in plugins/epan/wimax/msg_dlmap.c by validating a length field.
CVE-2020-7062
- EPSS 1.2%
 - Published 27.02.2020 21:15:19
 - Last modified 21.11.2024 05:36:35
 
In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set to 0 (disabled), and the file upload fails, the upl...