CVE-2020-12460
- EPSS 14.59%
- Published 27.07.2020 23:15:12
- Last modified 21.11.2024 04:59:44
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a specially crafted DMARC aggregate report. This can cau...
CVE-2020-15103
- EPSS 0.26%
- Published 27.07.2020 18:15:13
- Last modified 21.11.2024 05:04:48
In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not checked against local surface coordinates and blindl...
CVE-2020-15953
- EPSS 1.23%
- Published 27.07.2020 07:15:10
- Last modified 21.11.2024 05:06:31
LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a meddler-in-th...
CVE-2020-15917
- EPSS 2.24%
- Published 23.07.2020 19:15:10
- Last modified 21.11.2024 05:06:26
common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
CVE-2020-6524
- EPSS 3.23%
- Published 22.07.2020 17:15:14
- Last modified 21.11.2024 05:35:53
Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6525
- EPSS 1.61%
- Published 22.07.2020 17:15:14
- Last modified 21.11.2024 05:35:53
Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6526
- EPSS 0.87%
- Published 22.07.2020 17:15:14
- Last modified 21.11.2024 05:35:54
Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVE-2020-6527
- EPSS 0.62%
- Published 22.07.2020 17:15:14
- Last modified 21.11.2024 05:35:54
Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVE-2020-6528
- EPSS 1.61%
- Published 22.07.2020 17:15:14
- Last modified 21.11.2024 05:35:54
Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2020-6529
- EPSS 0.4%
- Published 22.07.2020 17:15:14
- Last modified 21.11.2024 05:35:54
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page.