CVE-2020-10672
- EPSS 40.66%
- Veröffentlicht 18.03.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:49
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
CVE-2020-10673
- EPSS 20.9%
- Veröffentlicht 18.03.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:49
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
CVE-2019-12921
- EPSS 5.55%
- Veröffentlicht 18.03.2020 19:15:16
- Zuletzt bearbeitet 21.11.2024 04:23:49
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
CVE-2019-20326
- EPSS 3.96%
- Veröffentlicht 16.03.2020 22:15:14
- Zuletzt bearbeitet 21.11.2024 04:38:16
A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary...
CVE-2020-7919
- EPSS 0.85%
- Veröffentlicht 16.03.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:00
Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.
CVE-2020-1740
- EPSS 0.04%
- Veröffentlicht 16.03.2020 16:15:14
- Zuletzt bearbeitet 21.11.2024 05:11:17
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp a...
CVE-2020-1735
- EPSS 0.14%
- Veröffentlicht 16.03.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:16
A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believ...
CVE-2020-1753
- EPSS 0.04%
- Veröffentlicht 16.03.2020 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:18
A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2.9.x versions prior to 2.9.7, when managing kubernetes using the k8s module. Sensitive parameters suc...
CVE-2020-0556
- EPSS 0.16%
- Veröffentlicht 12.03.2020 21:15:14
- Zuletzt bearbeitet 21.11.2024 04:53:45
Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access
CVE-2020-10531
- EPSS 0.76%
- Veröffentlicht 12.03.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:55:31
An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.