CVE-2013-7490
- EPSS 0.39%
- Veröffentlicht 11.09.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 02:01:08
An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption.
CVE-2020-25219
- EPSS 1.23%
- Veröffentlicht 09.09.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:17:41
url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.
CVE-2020-24379
- EPSS 1.11%
- Veröffentlicht 09.09.2020 19:15:21
- Zuletzt bearbeitet 21.11.2024 05:14:42
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
- EPSS 44.38%
- Veröffentlicht 09.09.2020 19:15:21
- Zuletzt bearbeitet 21.11.2024 05:16:12
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
- EPSS 0.03%
- Veröffentlicht 09.09.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:17:39
A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b...
CVE-2020-1968
- EPSS 0.84%
- Veröffentlicht 09.09.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:45
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the atta...
CVE-2020-24659
- EPSS 3.4%
- Veröffentlicht 04.09.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 05:15:26
An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no_renegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs. The crash happens in the app...
CVE-2020-7729
- EPSS 3.58%
- Veröffentlicht 03.09.2020 09:15:10
- Zuletzt bearbeitet 21.11.2024 05:37:41
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
CVE-2020-24654
- EPSS 0.84%
- Veröffentlicht 02.09.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:15:23
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
CVE-2020-15810
- EPSS 0.21%
- Veröffentlicht 02.09.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:06:13
An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggling attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser s...