CVE-2020-28049
- EPSS 0.04%
- Veröffentlicht 04.11.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:22:16
An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attack...
CVE-2020-8037
- EPSS 0.22%
- Veröffentlicht 04.11.2020 18:15:20
- Zuletzt bearbeitet 21.11.2024 05:38:16
The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
CVE-2020-6557
- EPSS 0.82%
- Veröffentlicht 03.11.2020 03:15:16
- Zuletzt bearbeitet 21.11.2024 05:35:57
Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
CVE-2020-16002
- EPSS 1.43%
- Veröffentlicht 03.11.2020 03:15:15
- Zuletzt bearbeitet 21.11.2024 05:06:39
Use after free in PDFium in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVE-2020-16003
- EPSS 1.91%
- Veröffentlicht 03.11.2020 03:15:15
- Zuletzt bearbeitet 21.11.2024 05:06:39
Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-16004
- EPSS 1.24%
- Veröffentlicht 03.11.2020 03:15:15
- Zuletzt bearbeitet 21.11.2024 05:06:39
Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-16005
- EPSS 1.24%
- Veröffentlicht 03.11.2020 03:15:15
- Zuletzt bearbeitet 21.11.2024 05:06:39
Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-16006
- EPSS 1.37%
- Veröffentlicht 03.11.2020 03:15:15
- Zuletzt bearbeitet 21.11.2024 05:06:39
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-16007
- EPSS 0.03%
- Veröffentlicht 03.11.2020 03:15:15
- Zuletzt bearbeitet 21.11.2024 05:06:39
Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem.
CVE-2020-16008
- EPSS 1.22%
- Veröffentlicht 03.11.2020 03:15:15
- Zuletzt bearbeitet 21.11.2024 05:06:39
Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet.