CVE-2020-36149
- EPSS 0.29%
- Veröffentlicht 08.02.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:28:49
Incorrect handling of input data in changeAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protection or near NULL pointer overwrite in case of no m...
CVE-2020-36150
- EPSS 0.33%
- Veröffentlicht 08.02.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:28:49
Incorrect handling of input data in loudness function in the libmysofa library 0.5 - 1.1 will lead to heap buffer overflow and access to unallocated memory block.
CVE-2020-36151
- EPSS 0.33%
- Veröffentlicht 08.02.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:28:49
Incorrect handling of input data in mysofa_resampler_reset_mem function in the libmysofa library 0.5 - 1.1 will lead to heap buffer overflow and overwriting large memory block.
CVE-2020-36152
- EPSS 1.45%
- Veröffentlicht 08.02.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:28:49
Buffer overflow in readDataVar in hdf/dataobject.c in Symonics libmysofa 0.5 - 1.1 allows attackers to execute arbitrary code via a crafted SOFA.
CVE-2020-36242
- EPSS 1.27%
- Veröffentlicht 07.02.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:29:08
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.
CVE-2020-14312
- EPSS 0.11%
- Veröffentlicht 06.02.2021 00:15:12
- Zuletzt bearbeitet 21.11.2024 05:02:59
A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat Enterprise Linux, where it listens on any interface and accepts queries from addresses outside of its local subnet. In p...
CVE-2020-36241
- EPSS 0.18%
- Veröffentlicht 05.02.2021 14:15:17
- Zuletzt bearbeitet 21.11.2024 05:29:08
autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the ...
CVE-2021-21289
- EPSS 2.5%
- Veröffentlicht 02.02.2021 19:15:14
- Zuletzt bearbeitet 21.11.2024 05:47:56
Mechanize is an open-source ruby library that makes automated web interaction easy. In Mechanize from version 2.0.0 and before version 2.7.7 there is a command injection vulnerability. Affected versions of mechanize allow for OS commands to be inject...
CVE-2021-3281
- EPSS 36.23%
- Veröffentlicht 02.02.2021 07:15:14
- Zuletzt bearbeitet 21.11.2024 06:21:12
In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal via an archive with absolute paths or relative path...
CVE-2020-28493
- EPSS 0.21%
- Veröffentlicht 01.02.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:22:54
This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punct...