CVE-2019-14575
- EPSS 0.06%
- Veröffentlicht 23.11.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:26:59
Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2019-14562
- EPSS 0.04%
- Veröffentlicht 23.11.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:26:58
Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access.
CVE-2020-20739
- EPSS 0.2%
- Veröffentlicht 20.11.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:12:15
im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
CVE-2020-20740
- EPSS 0.36%
- Veröffentlicht 20.11.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:12:15
PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version().
CVE-2020-28974
- EPSS 0.06%
- Veröffentlicht 20.11.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:23:25
A slab-out-of-bounds read in fbcon in the Linux kernel before 5.9.7 could be used by local attackers to read privileged information or potentially crash the kernel, aka CID-3c4e0dff2095. This occurs because KD_FONT_OP_COPY in drivers/tty/vt/vt.c can ...
CVE-2020-19667
- EPSS 0.11%
- Veröffentlicht 20.11.2020 16:15:15
- Zuletzt bearbeitet 21.11.2024 05:09:18
Stack-based buffer overflow and unconditional jump in ReadXPMImage in coders/xpm.c in ImageMagick 7.0.10-7.
CVE-2020-28941
- EPSS 0.06%
- Veröffentlicht 19.11.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:23:20
An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack, aka CID-d41227544427. This occurs because of an i...
CVE-2020-28948
- EPSS 76.22%
- Veröffentlicht 19.11.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:23:21
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
CVE-2020-28949
- EPSS 92.96%
- Veröffentlicht 19.11.2020 19:15:11
- Zuletzt bearbeitet 07.11.2025 22:03:27
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
CVE-2019-20933
- EPSS 93.97%
- Veröffentlicht 19.11.2020 02:15:11
- Zuletzt bearbeitet 21.11.2024 04:39:42
InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret).