CVE-2020-25269
- EPSS 0.67%
- Veröffentlicht 11.09.2020 05:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:49
An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0. The pgsql module contains a use after free vulnerability. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd ser...
CVE-2020-13920
- EPSS 0.15%
- Veröffentlicht 10.09.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:02:09
Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something ...
CVE-2020-6097
- EPSS 0.29%
- Veröffentlicht 10.09.2020 15:15:36
- Zuletzt bearbeitet 21.11.2024 05:35:05
An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denial-of-service. An attacker can ...
CVE-2020-25219
- EPSS 0.59%
- Veröffentlicht 09.09.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:17:41
url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.
CVE-2020-24379
- EPSS 1.11%
- Veröffentlicht 09.09.2020 19:15:21
- Zuletzt bearbeitet 21.11.2024 05:14:42
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
- EPSS 44.26%
- Veröffentlicht 09.09.2020 19:15:21
- Zuletzt bearbeitet 21.11.2024 05:16:12
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
CVE-2020-7068
- EPSS 0.8%
- Veröffentlicht 09.09.2020 18:15:23
- Zuletzt bearbeitet 21.11.2024 05:36:36
In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.
- EPSS 0.15%
- Veröffentlicht 09.09.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:39
In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctnetlink_parse_tuple_filter in net/netfilter/nf_connt...
- EPSS 0.08%
- Veröffentlicht 09.09.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:39
A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b...
CVE-2020-1968
- EPSS 0.84%
- Veröffentlicht 09.09.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:45
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the atta...