CVE-2020-17507
- EPSS 2.6%
- Veröffentlicht 12.08.2020 18:15:17
- Zuletzt bearbeitet 21.11.2024 05:08:15
An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read.
CVE-2020-12100
- EPSS 10.96%
- Veröffentlicht 12.08.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:14
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
CVE-2020-12673
- EPSS 1.13%
- Veröffentlicht 12.08.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:02
In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
CVE-2020-12674
- EPSS 8.71%
- Veröffentlicht 12.08.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:02
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
CVE-2020-16145
- EPSS 0.7%
- Veröffentlicht 12.08.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 05:06:50
Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.
CVE-2020-17487
- EPSS 0.52%
- Veröffentlicht 11.08.2020 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:08:12
radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in r_x509_parse_algorithmidentifier in libr/util/x509.c. This is due to a malformed object identifier in IMAGE_DIRECTORY_ENTRY_SECURITY.
CVE-2020-17367
- EPSS 0.14%
- Veröffentlicht 11.08.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:07:57
Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.
CVE-2020-17368
- EPSS 4.49%
- Veröffentlicht 11.08.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:07:57
Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.
CVE-2020-6070
- EPSS 0.65%
- Veröffentlicht 10.08.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:35:01
An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A specially crafted f2fs file can cause a logic flaw and out-of-bounds heap operations, resulting in code execution. An attacker can pro...
CVE-2020-9490
- EPSS 75.82%
- Veröffentlicht 07.08.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:40:45
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via ...