CVE-2020-15707
- EPSS 0.04%
- Veröffentlicht 29.07.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:06:04
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffe...
CVE-2020-11933
- EPSS 0.03%
- Veröffentlicht 29.07.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:58:56
cloud-init as managed by snapd on Ubuntu Core 16 and Ubuntu Core 18 devices was run without restrictions on every boot, which a physical attacker could exploit by crafting cloud-init user-data/meta-data via external media to perform arbitrary changes...
CVE-2020-11934
- EPSS 0.05%
- Veröffentlicht 29.07.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:58:56
It was discovered that snapctl user-open allowed altering the $XDG_DATA_DIRS environment variable when calling the system xdg-open. OpenURL() in usersession/userd/launcher.go would alter $XDG_DATA_DIRS to append a path to a directory controlled by th...
CVE-2020-15863
- EPSS 0.05%
- Veröffentlicht 28.07.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:06:20
hw/net/xgmac.c in the XGMAC Ethernet controller in QEMU before 07-20-2020 has a buffer overflow. This occurs during packet transmission and affects the highbank and midway emulated machines. A guest user or process could use this flaw to crash the QE...
CVE-2020-15900
- EPSS 12.14%
- Veröffentlicht 28.07.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:06:24
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and...
CVE-2020-15103
- EPSS 0.28%
- Veröffentlicht 27.07.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:04:48
In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not checked against local surface coordinates and blindl...
CVE-2020-6514
- EPSS 14.46%
- Veröffentlicht 22.07.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:35:52
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
CVE-2020-15890
- EPSS 1.33%
- Veröffentlicht 21.07.2020 22:15:12
- Zuletzt bearbeitet 03.11.2025 19:15:39
LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.
CVE-2020-3481
- EPSS 2.98%
- Veröffentlicht 20.07.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:31:09
A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.0 - 0.102.3 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to...
CVE-2020-14001
- EPSS 9.35%
- Veröffentlicht 17.07.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:19
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins w...