CVE-2019-17637
- EPSS 0.17%
- Veröffentlicht 15.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:40
In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external enti...
CVE-2020-13934
- EPSS 23.38%
- Veröffentlicht 14.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:10
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException co...
CVE-2020-13935
- EPSS 92.16%
- Veröffentlicht 14.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:10
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with inv...
- EPSS 1.22%
- Veröffentlicht 14.07.2020 14:15:17
- Zuletzt bearbeitet 21.11.2024 05:01:46
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbo...
CVE-2019-20907
- EPSS 0.32%
- Veröffentlicht 13.07.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 04:39:39
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
CVE-2020-11061
- EPSS 0.91%
- Veröffentlicht 10.07.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:42
In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mi...
CVE-2020-10756
- EPSS 0.03%
- Veröffentlicht 09.07.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:56:00
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious...
CVE-2020-12399
- EPSS 0.1%
- Veröffentlicht 09.07.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:59:38
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
CVE-2020-12402
- EPSS 0.1%
- Veröffentlicht 09.07.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:59:38
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to re...
CVE-2020-10745
- EPSS 19.66%
- Veröffentlicht 07.07.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:58
A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows a remote attacker could to cause the Samba server to consume excessive CPU use, resulting in a denia...