CVE-2020-1739
- EPSS 0.04%
- Veröffentlicht 12.03.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:16
A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could ta...
CVE-2020-10108
- EPSS 3.72%
- Veröffentlicht 12.03.2020 13:15:12
- Zuletzt bearbeitet 25.11.2024 18:12:24
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as ...
CVE-2020-10109
- EPSS 2.52%
- Veröffentlicht 12.03.2020 13:15:12
- Zuletzt bearbeitet 25.11.2024 18:12:24
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipel...
- EPSS 0.04%
- Veröffentlicht 11.03.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:16
A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in ...
CVE-2020-0034
- EPSS 5.42%
- Veröffentlicht 10.03.2020 20:15:20
- Zuletzt bearbeitet 21.11.2024 04:52:47
In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User i...
- EPSS 1.99%
- Veröffentlicht 10.03.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:33:46
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker ...
CVE-2012-1096
- EPSS 0.35%
- Veröffentlicht 10.03.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 01:36:24
NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.
CVE-2020-10232
- EPSS 1.41%
- Veröffentlicht 09.03.2020 00:15:10
- Zuletzt bearbeitet 21.11.2024 04:55:01
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c.
CVE-2019-20503
- EPSS 2.47%
- Veröffentlicht 06.03.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 04:38:38
usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.
- EPSS 8.55%
- Veröffentlicht 06.03.2020 15:15:14
- Zuletzt bearbeitet 21.11.2024 04:54:55
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.