CVE-2020-6418
- EPSS 86.79%
- Published 27.02.2020 23:15:12
- Last modified 05.02.2025 13:56:44
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-9428
- EPSS 8.18%
- Published 27.02.2020 23:15:12
- Last modified 21.11.2024 05:40:37
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c by using more careful sscanf parsing.
CVE-2020-9430
- EPSS 3.61%
- Published 27.02.2020 23:15:12
- Last modified 21.11.2024 05:40:37
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addressed in plugins/epan/wimax/msg_dlmap.c by validating a length field.
CVE-2020-7041
- EPSS 1.79%
- Published 27.02.2020 18:15:11
- Last modified 21.11.2024 05:36:32
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a successful return value.
CVE-2020-7042
- EPSS 0.84%
- Published 27.02.2020 18:15:11
- Last modified 21.11.2024 05:36:32
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (o...
CVE-2020-7043
- EPSS 0.64%
- Published 27.02.2020 18:15:11
- Last modified 21.11.2024 05:36:32
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com att...
CVE-2020-9274
- EPSS 11.89%
- Published 26.02.2020 16:15:19
- Last modified 21.11.2024 05:40:19
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the...
CVE-2020-9391
- EPSS 0.16%
- Published 25.02.2020 18:15:11
- Last modified 21.11.2024 05:40:32
An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to ...
CVE-2020-8793
- EPSS 0.79%
- Published 25.02.2020 17:15:13
- Last modified 21.11.2024 05:39:26
OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.
- EPSS 88.14%
- Published 25.02.2020 17:15:13
- Last modified 21.11.2024 05:39:27
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the se...