CVE-2020-11100
- EPSS 74.79%
- Veröffentlicht 02.04.2020 15:15:17
- Zuletzt bearbeitet 21.11.2024 04:56:47
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
CVE-2020-1927
- EPSS 11.3%
- Veröffentlicht 02.04.2020 00:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:37
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
CVE-2020-1934
- EPSS 41.87%
- Veröffentlicht 01.04.2020 20:15:15
- Zuletzt bearbeitet 21.11.2024 05:11:38
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
CVE-2020-7064
- EPSS 2.33%
- Veröffentlicht 01.04.2020 04:15:13
- Zuletzt bearbeitet 21.11.2024 05:36:36
In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data() function, it is possible for malicious data to cause PHP to read one byte of uninitialized memory. This could potentially lead ...
CVE-2020-7065
- EPSS 5.02%
- Veröffentlicht 01.04.2020 04:15:13
- Zuletzt bearbeitet 21.11.2024 05:36:36
In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and pote...
CVE-2020-6814
- EPSS 0.84%
- Veröffentlicht 25.03.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:36:13
Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This...
CVE-2020-6805
- EPSS 1.52%
- Veröffentlicht 25.03.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:36:12
When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Fir...
CVE-2020-6806
- EPSS 6.05%
- Veröffentlicht 25.03.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:36:12
By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affect...
CVE-2020-6807
- EPSS 1.39%
- Veröffentlicht 25.03.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:36:13
When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash. This vulnerability affects Th...
CVE-2020-6811
- EPSS 1.84%
- Veröffentlicht 25.03.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:36:13
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted...