CVE-2020-8992
- EPSS 0.05%
- Veröffentlicht 14.02.2020 05:15:13
- Zuletzt bearbeitet 21.11.2024 05:39:47
ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size.
- EPSS 0.14%
- Veröffentlicht 12.02.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:40
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able t...
CVE-2018-14553
- EPSS 0.98%
- Veröffentlicht 11.02.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 03:49:18
gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).
CVE-2020-5529
- EPSS 1.64%
- Veröffentlicht 11.02.2020 12:15:21
- Zuletzt bearbeitet 21.11.2024 05:34:13
HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Andro...
CVE-2019-11482
- EPSS 0.09%
- Veröffentlicht 08.02.2020 05:15:13
- Zuletzt bearbeitet 21.11.2024 04:21:10
Sander Bos discovered a time of check to time of use (TOCTTOU) vulnerability in apport that allowed a user to cause core files to be written in arbitrary directories.
CVE-2019-11483
- EPSS 0.07%
- Veröffentlicht 08.02.2020 05:15:13
- Zuletzt bearbeitet 03.11.2025 20:15:42
Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user.
CVE-2019-11484
- EPSS 0.1%
- Veröffentlicht 08.02.2020 05:15:13
- Zuletzt bearbeitet 21.11.2024 04:21:10
Kevin Backhouse discovered an integer overflow in bson_ensure_space, as used in whoopsie.
CVE-2019-11485
- EPSS 0.09%
- Veröffentlicht 08.02.2020 05:15:13
- Zuletzt bearbeitet 21.11.2024 04:21:10
Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users to prevent crash handling.
CVE-2019-11481
- EPSS 0.13%
- Veröffentlicht 08.02.2020 05:15:12
- Zuletzt bearbeitet 21.11.2024 04:21:10
Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic link, a user could get apport to read any file on the system as root, with unknown consequences.
CVE-2020-1700
- EPSS 0.31%
- Veröffentlicht 07.02.2020 21:15:10
- Zuletzt bearbeitet 21.11.2024 05:11:11
A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket connection by radosgw. This flaw c...