CVE-2020-24659
- EPSS 3.4%
- Veröffentlicht 04.09.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 05:15:26
An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no_renegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs. The crash happens in the app...
CVE-2020-24977
- EPSS 0.5%
- Veröffentlicht 04.09.2020 00:15:10
- Zuletzt bearbeitet 21.11.2024 05:16:15
GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.
CVE-2020-15094
- EPSS 2.25%
- Veröffentlicht 02.09.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:04:47
In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restorati...
CVE-2020-24553
- EPSS 0.18%
- Veröffentlicht 02.09.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:14:58
Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header.
CVE-2020-24654
- EPSS 0.84%
- Veröffentlicht 02.09.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:15:23
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
CVE-2020-15810
- EPSS 0.21%
- Veröffentlicht 02.09.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:06:13
An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggling attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser s...
CVE-2020-15811
- EPSS 0.25%
- Veröffentlicht 02.09.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:06:13
An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser s...
CVE-2020-16150
- EPSS 0.08%
- Veröffentlicht 02.09.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:06:51
A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed time difference based on a pa...
CVE-2020-24583
- EPSS 3.43%
- Veröffentlicht 01.09.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:15:03
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level directories created in the process of uploading file...
CVE-2020-24584
- EPSS 3.29%
- Veröffentlicht 01.09.2020 13:15:11
- Zuletzt bearbeitet 21.11.2024 05:15:03
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.