CVE-2020-25695
- EPSS 23.76%
- Veröffentlicht 16.11.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:29
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions un...
CVE-2020-8695
- EPSS 0.15%
- Veröffentlicht 12.11.2020 18:15:16
- Zuletzt bearbeitet 21.11.2024 05:39:16
Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
CVE-2020-8696
- EPSS 0.24%
- Veröffentlicht 12.11.2020 18:15:16
- Zuletzt bearbeitet 21.11.2024 05:39:16
Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2020-8698
- EPSS 0.27%
- Veröffentlicht 12.11.2020 18:15:16
- Zuletzt bearbeitet 21.11.2024 05:39:17
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2020-25706
- EPSS 1.46%
- Veröffentlicht 12.11.2020 14:15:22
- Zuletzt bearbeitet 21.11.2024 05:18:32
A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template import preview in the xml_path field
CVE-2020-28368
- EPSS 0.07%
- Veröffentlicht 10.11.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:22:40
Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically i...
CVE-2020-25074
- EPSS 12.81%
- Veröffentlicht 10.11.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:12
The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use this to achieve remote code execution.
CVE-2017-18926
- EPSS 2.91%
- Veröffentlicht 06.11.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 03:21:16
raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen in raptor_qname_format_as_xml).
CVE-2020-16846
- EPSS 94.39%
- Veröffentlicht 06.11.2020 08:15:13
- Zuletzt bearbeitet 07.11.2025 19:32:05
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
CVE-2020-17490
- EPSS 0.05%
- Veröffentlicht 06.11.2020 08:15:13
- Zuletzt bearbeitet 21.11.2024 05:08:13
The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions.