CVE-2020-24386
- EPSS 0.63%
- Published 04.01.2021 17:15:13
- Last modified 21.11.2024 05:14:43
An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).
CVE-2020-25275
- EPSS 6.85%
- Published 04.01.2021 17:15:13
- Last modified 21.11.2024 05:17:50
Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.
CVE-2020-35496
- EPSS 0.05%
- Published 04.01.2021 15:15:14
- Last modified 21.11.2024 05:27:25
There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to applicat...
CVE-2020-35494
- EPSS 0.21%
- Published 04.01.2021 15:15:13
- Last modified 21.11.2024 05:27:25
There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to da...
CVE-2020-35495
- EPSS 0.21%
- Published 04.01.2021 15:15:13
- Last modified 21.11.2024 05:27:25
There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw ...
CVE-2020-35493
- EPSS 0.3%
- Published 04.01.2021 15:15:12
- Last modified 21.11.2024 05:27:24
A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects ...
CVE-2020-35884
- EPSS 0.24%
- Published 31.12.2020 10:15:16
- Last modified 21.11.2024 05:28:24
An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.
CVE-2020-35730
- EPSS 55.3%
- Published 28.12.2020 20:15:13
- Last modified 21.02.2025 22:38:53
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcu...
CVE-2020-35738
- EPSS 0.41%
- Published 28.12.2020 04:15:12
- Last modified 21.11.2024 05:27:59
WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.
CVE-2020-35376
- EPSS 0.45%
- Published 26.12.2020 04:15:12
- Last modified 21.11.2024 05:27:14
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.