CVE-2020-24583
- EPSS 3.43%
- Veröffentlicht 01.09.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:15:03
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level directories created in the process of uploading file...
CVE-2020-24584
- EPSS 3.29%
- Veröffentlicht 01.09.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:15:03
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.
- EPSS 10%
- Veröffentlicht 31.08.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:03:05
An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_tok...
CVE-2020-14352
- EPSS 4.04%
- Veröffentlicht 30.08.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:03:04
A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the...
CVE-2020-24972
- EPSS 21.34%
- Veröffentlicht 29.08.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:16:15
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line opti...
CVE-2020-24661
- EPSS 0.25%
- Veröffentlicht 26.08.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:15:27
GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system-provided PKCS#11 store. This ...
CVE-2020-24614
- EPSS 6.4%
- Veröffentlicht 25.08.2020 14:15:16
- Zuletzt bearbeitet 21.11.2024 05:15:09
Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.
CVE-2020-24606
- EPSS 6.34%
- Veröffentlicht 24.08.2020 18:15:10
- Zuletzt bearbeitet 21.11.2024 05:15:08
Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digest...
- EPSS 0.27%
- Veröffentlicht 24.08.2020 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:03:06
A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writing, chronyd does not check fo...
CVE-2020-8622
- EPSS 0.67%
- Veröffentlicht 21.08.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:39:08
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed re...