CVE-2020-2026
- EPSS 0.21%
- Published 10.06.2020 18:15:11
- Last modified 21.11.2024 05:24:29
A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for cod...
CVE-2020-13977
- EPSS 1.87%
- Published 09.06.2020 14:15:10
- Last modified 21.11.2024 05:02:16
Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson....
CVE-2020-10757
- EPSS 0.41%
- Published 09.06.2020 13:15:10
- Last modified 21.11.2024 04:56:00
A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.
CVE-2020-13964
- EPSS 0.87%
- Published 09.06.2020 03:15:11
- Last modified 21.11.2024 05:02:15
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.
CVE-2020-13965
- EPSS 85.2%
- Published 09.06.2020 03:15:11
- Last modified 13.02.2025 20:02:23
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
CVE-2020-13962
- EPSS 1.57%
- Published 09.06.2020 00:15:10
- Last modified 21.11.2024 05:02:14
Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session ...
CVE-2020-10754
- EPSS 0.25%
- Published 08.06.2020 18:15:10
- Last modified 21.11.2024 04:56:00
It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happe...
CVE-2020-13625
- EPSS 2.74%
- Published 08.06.2020 17:15:10
- Last modified 21.11.2024 05:01:37
PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.
CVE-2020-13696
- EPSS 0.04%
- Published 08.06.2020 17:15:10
- Last modified 21.11.2024 05:01:45
An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local attacker wi...
CVE-2020-12695
- EPSS 4.73%
- Published 08.06.2020 17:15:09
- Last modified 21.11.2024 05:00:05
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger is...