CVE-2020-35176
- EPSS 1.57%
- Published 12.12.2020 00:15:12
- Last modified 21.11.2024 05:26:54
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incompl...
CVE-2020-26418
- EPSS 0.41%
- Published 11.12.2020 19:15:12
- Last modified 21.11.2024 05:19:54
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
CVE-2020-26419
- EPSS 0.43%
- Published 11.12.2020 19:15:12
- Last modified 21.11.2024 05:19:54
Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.
CVE-2020-26420
- EPSS 0.43%
- Published 11.12.2020 19:15:12
- Last modified 21.11.2024 05:19:54
Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
CVE-2020-26421
- EPSS 0.26%
- Published 11.12.2020 19:15:12
- Last modified 21.11.2024 05:19:54
Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
CVE-2020-35132
- EPSS 0.52%
- Published 11.12.2020 05:15:12
- Last modified 21.11.2024 05:26:49
An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.
CVE-2020-27828
- EPSS 0.16%
- Published 11.12.2020 04:15:11
- Last modified 21.11.2024 05:21:53
There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availabili...
CVE-2020-29668
- EPSS 1.04%
- Published 10.12.2020 08:15:11
- Last modified 21.11.2024 05:24:24
Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.
CVE-2020-16592
- EPSS 0.31%
- Published 09.12.2020 21:15:15
- Last modified 21.11.2024 05:07:10
A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file.
CVE-2020-26257
- EPSS 0.45%
- Published 09.12.2020 19:15:11
- Last modified 21.11.2024 05:19:40
Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying a different room id...