CVE-2020-11080
- EPSS 0.68%
- Veröffentlicht 03.06.2020 23:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:44
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings e...
CVE-2020-13379
- EPSS 92.95%
- Veröffentlicht 03.06.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:01:08
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can b...
- EPSS 3.6%
- Veröffentlicht 03.06.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:59
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending...
CVE-2020-13254
- EPSS 8.67%
- Veröffentlicht 03.06.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:00:53
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.
CVE-2020-13596
- EPSS 0.99%
- Veröffentlicht 03.06.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:34
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.
CVE-2020-13776
- EPSS 0.13%
- Veröffentlicht 03.06.2020 03:15:10
- Zuletzt bearbeitet 09.06.2025 16:15:31
systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because...
CVE-2020-13775
- EPSS 0.97%
- Veröffentlicht 02.06.2020 23:15:10
- Zuletzt bearbeitet 21.11.2024 05:01:50
ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) if echo-message is not enabled and there is no network.
- EPSS 9.9%
- Veröffentlicht 02.06.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:01:11
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial o...
CVE-2020-13757
- EPSS 0.08%
- Veröffentlicht 01.06.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:01:47
Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted cipherte...
CVE-2020-12867
- EPSS 0.11%
- Veröffentlicht 01.06.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:00:27
A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.