CVE-2020-25681
- EPSS 20.27%
- Veröffentlicht 20.01.2021 17:15:12
- Zuletzt bearbeitet 04.11.2025 20:15:56
A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in the way RRSets are sorted before validating with DNSSEC data. An attacker on the network, who can forge DNS replies such as that they are accepted as vali...
CVE-2020-25682
- EPSS 34.29%
- Veröffentlicht 20.01.2021 17:15:12
- Zuletzt bearbeitet 04.11.2025 20:15:56
A flaw was found in dnsmasq before 2.83. A buffer overflow vulnerability was discovered in the way dnsmasq extract names from DNS packets before validating them with DNSSEC data. An attacker on the network, who can create valid DNS replies, could use...
CVE-2020-25683
- EPSS 31.32%
- Veröffentlicht 20.01.2021 16:15:14
- Zuletzt bearbeitet 04.11.2025 20:15:57
A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. A remote attacker, who can create valid DNS replies, could use this flaw ...
CVE-2020-25684
- EPSS 0.29%
- Veröffentlicht 20.01.2021 16:15:14
- Zuletzt bearbeitet 04.11.2025 20:15:57
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the a...
CVE-2020-25685
- EPSS 0.36%
- Veröffentlicht 20.01.2021 16:15:14
- Zuletzt bearbeitet 04.11.2025 20:15:57
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak...
CVE-2020-14409
- EPSS 0.2%
- Veröffentlicht 19.01.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:03:12
SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.
CVE-2020-14410
- EPSS 0.16%
- Veröffentlicht 19.01.2021 20:15:12
- Zuletzt bearbeitet 20.03.2025 17:01:20
SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafted .BMP file.
CVE-2021-20190
- EPSS 0.5%
- Veröffentlicht 19.01.2021 17:15:13
- Zuletzt bearbeitet 27.08.2025 21:15:36
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVE-2021-3181
- EPSS 3%
- Veröffentlicht 19.01.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 06:21:04
rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). A small email me...
CVE-2021-3178
- EPSS 0.16%
- Veröffentlicht 19.01.2021 07:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:04
fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some parties argue that such a subdirecto...