CVE-2020-7729
- EPSS 2.42%
- Veröffentlicht 03.09.2020 09:15:10
- Zuletzt bearbeitet 21.11.2024 05:37:41
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
CVE-2020-24654
- EPSS 0.85%
- Veröffentlicht 02.09.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:15:23
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
CVE-2020-15810
- EPSS 0.16%
- Veröffentlicht 02.09.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:06:13
An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggling attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser s...
CVE-2020-15811
- EPSS 0.19%
- Veröffentlicht 02.09.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:06:13
An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser s...
CVE-2020-16150
- EPSS 0.08%
- Veröffentlicht 02.09.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:06:51
A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed time difference based on a pa...
- EPSS 12.89%
- Veröffentlicht 31.08.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:03:05
An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_tok...
CVE-2020-12829
- EPSS 0.12%
- Veröffentlicht 31.08.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 05:00:21
In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback. A local attacker could abuse t...
CVE-2020-25032
- EPSS 0.9%
- Veröffentlicht 31.08.2020 04:15:12
- Zuletzt bearbeitet 21.11.2024 05:16:42
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
CVE-2020-8244
- EPSS 1.14%
- Veröffentlicht 30.08.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:34
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, ...
CVE-2019-14904
- EPSS 0.04%
- Veröffentlicht 26.08.2020 03:15:11
- Zuletzt bearbeitet 21.11.2024 04:27:39
A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the remote machine. An attacker coul...