CVE-2020-11099
- EPSS 0.18%
- Veröffentlicht 22.06.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:47
In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_license_packet. A manipulated license packet can lead to out of bound reads to an internal buffer. This is fixed in version 2.1.2.
CVE-2020-11095
- EPSS 0.26%
- Veröffentlicht 22.06.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:46
In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.
CVE-2020-14954
- EPSS 21.7%
- Veröffentlicht 21.06.2020 17:15:09
- Zuletzt bearbeitet 21.11.2024 05:04:30
Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates i...
CVE-2020-8184
- EPSS 1.07%
- Veröffentlicht 19.06.2020 17:15:18
- Zuletzt bearbeitet 21.11.2024 05:38:27
A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.
CVE-2020-3350
- EPSS 0.14%
- Veröffentlicht 18.06.2020 03:15:14
- Zuletzt bearbeitet 21.11.2024 05:30:51
A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability is due to a race condition th...
CVE-2020-8619
- EPSS 6.93%
- Veröffentlicht 17.06.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:39:08
In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone ...
CVE-2020-8618
- EPSS 1.3%
- Veröffentlicht 17.06.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:39:08
An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.
CVE-2020-14402
- EPSS 2.22%
- Veröffentlicht 17.06.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:03:11
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings.
CVE-2020-14403
- EPSS 1.11%
- Veröffentlicht 17.06.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:03:11
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/hextile.c allows out-of-bounds access via encodings.
CVE-2020-14404
- EPSS 1.33%
- Veröffentlicht 17.06.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:03:11
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings.