CVE-2020-1934
- EPSS 22.52%
- Veröffentlicht 01.04.2020 20:15:15
- Zuletzt bearbeitet 21.11.2024 05:11:38
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
CVE-2020-7066
- EPSS 1.37%
- Veröffentlicht 01.04.2020 04:15:14
- Zuletzt bearbeitet 21.11.2024 05:36:36
In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make in...
CVE-2020-7064
- EPSS 3.18%
- Veröffentlicht 01.04.2020 04:15:13
- Zuletzt bearbeitet 21.11.2024 05:36:36
In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data() function, it is possible for malicious data to cause PHP to read one byte of uninitialized memory. This could potentially lead ...
CVE-2020-7065
- EPSS 7.27%
- Veröffentlicht 01.04.2020 04:15:13
- Zuletzt bearbeitet 21.11.2024 05:36:36
In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and pote...
CVE-2020-5291
- EPSS 0.19%
- Veröffentlicht 31.03.2020 18:15:26
- Zuletzt bearbeitet 21.11.2024 05:33:50
Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can i...
CVE-2020-1712
- EPSS 0.11%
- Veröffentlicht 31.03.2020 17:15:26
- Zuletzt bearbeitet 21.11.2024 05:11:13
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially...
CVE-2020-10595
- EPSS 7.3%
- Veröffentlicht 31.03.2020 13:15:13
- Zuletzt bearbeitet 21.11.2024 04:55:39
pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental prompting by a Kerberos library. It may overflow a buffer provided by the underlying Kerberos library by a single '\0' byte if an at...
CVE-2020-11111
- EPSS 2.26%
- Veröffentlicht 31.03.2020 05:15:13
- Zuletzt bearbeitet 21.11.2024 04:56:48
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
CVE-2020-11112
- EPSS 9.59%
- Veröffentlicht 31.03.2020 05:15:13
- Zuletzt bearbeitet 21.11.2024 04:56:49
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
CVE-2020-11113
- EPSS 61.24%
- Veröffentlicht 31.03.2020 05:15:13
- Zuletzt bearbeitet 21.11.2024 04:56:49
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).