CVE-2020-3811
- EPSS 0.42%
- Veröffentlicht 26.05.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 05:31:47
qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.
CVE-2020-3812
- EPSS 0.05%
- Veröffentlicht 26.05.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 05:31:47
qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence o...
CVE-2020-13434
- EPSS 0.06%
- Veröffentlicht 24.05.2020 22:15:10
- Zuletzt bearbeitet 21.11.2024 05:01:15
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
CVE-2020-13396
- EPSS 0.5%
- Veröffentlicht 22.05.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:01:10
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
CVE-2020-13397
- EPSS 0.08%
- Veröffentlicht 22.05.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:01:10
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in security_fips_decrypt in libfreerdp/core/security.c due to an uninitialized value.
CVE-2020-13398
- EPSS 0.46%
- Veröffentlicht 22.05.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:01:10
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.
CVE-2020-10711
- EPSS 5.44%
- Veröffentlicht 22.05.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:54
A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the...
CVE-2020-11076
- EPSS 1.78%
- Veröffentlicht 22.05.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:44
In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.
CVE-2020-11077
- EPSS 0.82%
- Veröffentlicht 22.05.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:44
In Puma (RubyGem) before 4.3.5 and 3.12.6, a client could smuggle a request through a proxy, causing the proxy to send a response back to another unknown client. If the proxy uses persistent connections and the client adds another request in via HTTP...
CVE-2020-12693
- EPSS 0.63%
- Veröffentlicht 21.05.2020 23:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:05
Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A race condition allows a user to launch a process as an arbitrary user.