- EPSS 66.83%
- Veröffentlicht 20.02.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:40:19
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
CVE-2019-20479
- EPSS 0.47%
- Veröffentlicht 20.02.2020 06:15:11
- Zuletzt bearbeitet 21.11.2024 04:38:34
A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.
CVE-2014-4678
- EPSS 4.73%
- Veröffentlicht 20.02.2020 03:15:10
- Zuletzt bearbeitet 21.11.2024 02:10:41
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-465...
CVE-2020-6061
- EPSS 1.77%
- Veröffentlicht 19.02.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:00
An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS reque...
CVE-2020-6062
- EPSS 8.33%
- Veröffentlicht 19.02.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:00
An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to send an HTTP request to trigge...
CVE-2015-0258
- EPSS 16.5%
- Veröffentlicht 17.02.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 02:22:40
Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) ...
CVE-2020-8518
- EPSS 84.86%
- Veröffentlicht 17.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:38:59
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
CVE-2019-10785
- EPSS 0.24%
- Veröffentlicht 13.02.2020 17:15:29
- Zuletzt bearbeitet 21.11.2024 04:19:55
dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.
CVE-2020-8955
- EPSS 14.21%
- Veröffentlicht 12.02.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:39:44
irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malformed IRC message 324 (channel m...
- EPSS 0.16%
- Veröffentlicht 12.02.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:40
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able t...