CVE-2020-12100
- EPSS 19.61%
- Veröffentlicht 12.08.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:14
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
CVE-2020-12673
- EPSS 4.38%
- Veröffentlicht 12.08.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:02
In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
CVE-2020-12674
- EPSS 21.31%
- Veröffentlicht 12.08.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:02
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
CVE-2020-17446
- EPSS 2.14%
- Veröffentlicht 12.08.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:08:07
asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, because of access to an uninitialized pointer in the array data decoder.
CVE-2020-17489
- EPSS 0.15%
- Veröffentlicht 11.08.2020 21:15:10
- Zuletzt bearbeitet 21.11.2024 05:08:13
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password show...
CVE-2020-0256
- EPSS 0.06%
- Veröffentlicht 11.08.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 04:53:11
In LoadPartitionTable of gpt.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege when inserting a malicious USB device, with no additional execution privileges needed. User inter...
CVE-2020-16092
- EPSS 0.04%
- Veröffentlicht 11.08.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:06:45
In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in ...
CVE-2020-17367
- EPSS 0.14%
- Veröffentlicht 11.08.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:07:57
Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.
CVE-2020-17368
- EPSS 4.49%
- Veröffentlicht 11.08.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:07:57
Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.
CVE-2020-9490
- EPSS 76.28%
- Veröffentlicht 07.08.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:40:45
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via ...