CVE-2020-20739
- EPSS 0.2%
- Veröffentlicht 20.11.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:12:15
im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
CVE-2020-20740
- EPSS 0.36%
- Veröffentlicht 20.11.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:12:15
PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version().
CVE-2020-13671
- EPSS 4.5%
- Veröffentlicht 20.11.2020 16:15:15
- Zuletzt bearbeitet 03.11.2025 18:06:21
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affec...
CVE-2020-4788
- EPSS 0.2%
- Veröffentlicht 20.11.2020 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:15
IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296.
CVE-2020-28924
- EPSS 0.35%
- Veröffentlicht 19.11.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:23:18
An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy than advertised. The suggested passwords depend deterministically on th...
CVE-2020-28941
- EPSS 0.06%
- Veröffentlicht 19.11.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:23:20
An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack, aka CID-d41227544427. This occurs because of an i...
CVE-2020-28948
- EPSS 76.22%
- Veröffentlicht 19.11.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:23:21
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
CVE-2020-28949
- EPSS 92.96%
- Veröffentlicht 19.11.2020 19:15:11
- Zuletzt bearbeitet 07.11.2025 22:03:27
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
CVE-2020-25703
- EPSS 0.31%
- Veröffentlicht 19.11.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:31
The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3....
CVE-2020-25698
- EPSS 0.7%
- Veröffentlicht 19.11.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:30
Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8,...