CVE-2020-25828
- EPSS 0.39%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:51
An issue was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. The non-jqueryMsg version of mw.message().parse() doesn't escape HTML. This affects both message contents (which are generally safe) and the parameters (whic...
CVE-2020-25869
- EPSS 0.27%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:56
An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. Handling of actor ID does not necessarily use the correct database or correct wiki.
CVE-2020-26116
- EPSS 0.58%
- Veröffentlicht 27.09.2020 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:19:16
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first ar...
CVE-2020-25596
- EPSS 0.09%
- Veröffentlicht 23.09.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:11
An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves various state sanitization activities to software. One of Xen's sanitization paths injects a #GP fault,...
CVE-2020-25597
- EPSS 0.11%
- Veröffentlicht 23.09.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:11
An issue was discovered in Xen through 4.14.x. There is mishandling of the constraint that once-valid event channels may not turn invalid. Logic in the handling of event channel operations in Xen assumes that an event channel, once valid, will not be...
CVE-2020-25598
- EPSS 0.07%
- Veröffentlicht 23.09.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:11
An issue was discovered in Xen 4.14.x. There is a missing unlock in the XENMEM_acquire_resource error path. The RCU (Read, Copy, Update) mechanism is a synchronisation primitive. A buggy error path in the XENMEM_acquire_resource exits without releasi...
- EPSS 0.07%
- Veröffentlicht 23.09.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:12
An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potentially by a guest on itself) or XEN_DOMCTL_soft_reset (by itself covered by XSA-77) can lead to the violation of various internal as...
CVE-2020-25600
- EPSS 0.1%
- Veröffentlicht 23.09.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:12
An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit x86 domains. The so called 2-level event channel model imposes different limits on the number of usable event channels for 32-bit x86 domains vs 64-bi...
CVE-2020-25601
- EPSS 0.08%
- Veröffentlicht 23.09.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:12
An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evtchn_destroy(). In particular, the FIFO event channel model allows guests to have a large number of event channels active at a time. Closing all of the...
- EPSS 0.08%
- Veröffentlicht 23.09.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:12
An issue was discovered in Xen through 4.14.x. An x86 PV guest can trigger a host OS crash when handling guest access to MSR_MISC_ENABLE. When a guest accesses certain Model Specific Registers, Xen first reads the value from hardware to use as the ba...