CVE-2020-25866
- EPSS 0.97%
- Published 06.10.2020 15:15:15
- Last modified 21.11.2024 05:18:56
In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/packet-blip.c by allowing reasona...
CVE-2020-26575
- EPSS 2.23%
- Published 06.10.2020 15:15:15
- Last modified 21.11.2024 05:20:06
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.
CVE-2020-25613
- EPSS 0.33%
- Published 06.10.2020 13:15:13
- Last modified 21.11.2024 05:18:14
An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issu...
CVE-2020-26571
- EPSS 0.04%
- Published 06.10.2020 02:15:13
- Last modified 21.11.2024 05:20:06
The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init.
CVE-2020-26572
- EPSS 0.05%
- Published 06.10.2020 02:15:13
- Last modified 21.11.2024 05:20:06
The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher.
CVE-2020-26570
- EPSS 0.05%
- Published 06.10.2020 02:15:12
- Last modified 21.11.2024 05:20:06
The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file.
CVE-2020-8223
- EPSS 0.27%
- Published 05.10.2020 14:15:13
- Last modified 21.11.2024 05:38:32
A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves.
CVE-2020-7069
- EPSS 9.21%
- Published 02.10.2020 15:15:12
- Last modified 21.11.2024 05:36:36
In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and inc...
CVE-2020-7070
- EPSS 26.09%
- Published 02.10.2020 15:15:12
- Last modified 21.11.2024 05:36:37
In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies that decode ...
CVE-2020-26519
- EPSS 0.77%
- Published 02.10.2020 06:15:12
- Last modified 21.11.2024 05:19:59
Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a denial of service.