CVE-2020-14148
- EPSS 1.82%
- Veröffentlicht 15.06.2020 18:15:15
- Zuletzt bearbeitet 21.11.2024 05:02:44
The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function.
CVE-2020-13999
- EPSS 0.33%
- Veröffentlicht 15.06.2020 16:15:22
- Zuletzt bearbeitet 21.11.2024 05:02:19
ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer overflow and denial of service via a crafted EMF file.
CVE-2020-0543
- EPSS 0.48%
- Veröffentlicht 15.06.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:53:42
Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2020-4046
- EPSS 6.85%
- Veröffentlicht 12.06.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:32:12
In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a higher privileged user, this coul...
CVE-2020-4047
- EPSS 5.57%
- Veröffentlicht 12.06.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:32:13
In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privilege...
CVE-2020-4048
- EPSS 3.5%
- Veröffentlicht 12.06.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:32:13
In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in version 5.4.2, along with all the ...
CVE-2020-4049
- EPSS 5.89%
- Veröffentlicht 12.06.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:32:13
In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload the theme, and is low severit...
- EPSS 2.42%
- Veröffentlicht 12.06.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:32:13
In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged b...
CVE-2020-0198
- EPSS 11.11%
- Veröffentlicht 11.06.2020 15:15:16
- Zuletzt bearbeitet 21.11.2024 04:53:05
In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product...
CVE-2020-0181
- EPSS 9.45%
- Veröffentlicht 11.06.2020 15:15:15
- Zuletzt bearbeitet 21.11.2024 04:53:03
In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploita...