CVE-2020-12268
- EPSS 0.81%
- Veröffentlicht 27.04.2020 02:15:12
- Zuletzt bearbeitet 21.11.2024 04:59:24
jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow.
CVE-2020-12137
- EPSS 5.22%
- Veröffentlicht 24.04.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:19
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, ...
CVE-2019-20788
- EPSS 0.8%
- Veröffentlicht 23.04.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:39:21
libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.
CVE-2020-11945
- EPSS 28.48%
- Veröffentlicht 23.04.2020 15:15:14
- Zuletzt bearbeitet 21.11.2024 04:58:57
An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a s...
CVE-2020-1760
- EPSS 0.35%
- Veröffentlicht 23.04.2020 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:11:19
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
CVE-2020-1983
- EPSS 0.2%
- Veröffentlicht 22.04.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:47
A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.
CVE-2020-12066
- EPSS 5.73%
- Veröffentlicht 22.04.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:59:12
CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
CVE-2020-11008
- EPSS 2.22%
- Veröffentlicht 21.04.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:56:34
Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open fo...
CVE-2020-1967
- EPSS 67.31%
- Veröffentlicht 21.04.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:45
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occur...
CVE-2020-11868
- EPSS 1.3%
- Veröffentlicht 17.04.2020 04:15:10
- Zuletzt bearbeitet 05.05.2025 17:15:57
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a vali...