CVE-2020-17367
- EPSS 0.14%
- Veröffentlicht 11.08.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:07:57
Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.
CVE-2020-17368
- EPSS 4.49%
- Veröffentlicht 11.08.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:07:57
Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.
CVE-2020-9490
- EPSS 75.82%
- Veröffentlicht 07.08.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:40:45
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via ...
CVE-2020-11984
- EPSS 76.31%
- Veröffentlicht 07.08.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:02
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
CVE-2020-11993
- EPSS 38.85%
- Veröffentlicht 07.08.2020 16:15:11
- Zuletzt bearbeitet 01.05.2025 15:40:19
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLev...
CVE-2020-16845
- EPSS 0.08%
- Veröffentlicht 06.08.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:07:15
Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.
CVE-2020-14347
- EPSS 0.02%
- Veröffentlicht 05.08.2020 14:15:12
- Zuletzt bearbeitet 29.08.2025 13:42:30
A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before v...
CVE-2020-17353
- EPSS 1.26%
- Veröffentlicht 05.08.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:07:56
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.
CVE-2020-16116
- EPSS 0.86%
- Veröffentlicht 03.08.2020 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:06:47
In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
CVE-2020-16166
- EPSS 1.85%
- Veröffentlicht 30.07.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:06:53
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c...