CVE-2020-35884
- EPSS 0.24%
- Veröffentlicht 31.12.2020 10:15:16
- Zuletzt bearbeitet 21.11.2024 05:28:24
An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.
CVE-2020-35730
- EPSS 69.03%
- Veröffentlicht 28.12.2020 20:15:13
- Zuletzt bearbeitet 04.11.2025 15:00:19
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcu...
CVE-2020-35738
- EPSS 0.41%
- Veröffentlicht 28.12.2020 04:15:12
- Zuletzt bearbeitet 21.11.2024 05:27:59
WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.
CVE-2020-35376
- EPSS 0.45%
- Veröffentlicht 26.12.2020 04:15:12
- Zuletzt bearbeitet 21.11.2024 05:27:14
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.
CVE-2020-29385
- EPSS 0.63%
- Veröffentlicht 26.12.2020 02:15:12
- Zuletzt bearbeitet 29.04.2025 13:13:41
GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The next execution in the loop wi...
CVE-2020-35679
- EPSS 1.71%
- Veröffentlicht 24.12.2020 16:15:15
- Zuletzt bearbeitet 21.11.2024 05:27:49
smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to an instance that performs many regex lookups.
CVE-2020-35680
- EPSS 4.23%
- Veröffentlicht 24.12.2020 16:15:15
- Zuletzt bearbeitet 21.11.2024 05:27:49
smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted pattern of client activity, because the filter state machine doe...
- EPSS 7.54%
- Veröffentlicht 21.12.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:21:55
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
CVE-2020-27781
- EPSS 0.07%
- Veröffentlicht 18.12.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:21:49
User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. ...
CVE-2020-35474
- EPSS 0.47%
- Veröffentlicht 18.12.2020 08:15:15
- Zuletzt bearbeitet 21.11.2024 05:27:21
In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so that the output is raw HTML.