CVE-2020-7238
- EPSS 0.69%
- Published 27.01.2020 17:15:12
- Last modified 21.11.2024 05:36:53
Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869...
CVE-2014-8161
- EPSS 0.58%
- Published 27.01.2020 16:15:10
- Last modified 21.11.2024 02:18:41
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
CVE-2015-0241
- EPSS 2.93%
- Published 27.01.2020 16:15:10
- Last modified 21.11.2024 02:22:38
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1)...
CVE-2015-0242
- EPSS 2.2%
- Published 27.01.2020 16:15:10
- Last modified 21.11.2024 02:22:38
Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on a Windows system, allows remote authenticated users...
CVE-2015-0243
- EPSS 3.13%
- Published 27.01.2020 16:15:10
- Last modified 21.11.2024 02:22:38
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute...
CVE-2015-0244
- EPSS 1.08%
- Published 27.01.2020 16:15:10
- Last modified 21.11.2024 02:22:38
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafte...
CVE-2015-0294
- EPSS 0.58%
- Published 27.01.2020 16:15:10
- Last modified 21.11.2024 02:22:45
GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
CVE-2020-8003
- EPSS 0.04%
- Published 27.01.2020 05:15:13
- Last modified 21.11.2024 05:38:11
A double-free vulnerability in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service by triggering texture allocation failure, because vrend_renderer_resource_allocated_texture is not an appropriate place for a...
CVE-2020-8002
- EPSS 0.04%
- Published 27.01.2020 05:15:12
- Last modified 21.11.2024 05:38:11
A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service via commands that attempt to launch a grid without previously providing a Compute Shader (CS).
CVE-2019-20421
- EPSS 3.07%
- Published 27.01.2020 05:15:10
- Last modified 21.11.2024 04:38:25
In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.