CVE-2020-14540
- EPSS 0.45%
- Veröffentlicht 15.07.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:03:29
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access v...
- EPSS 1.43%
- Veröffentlicht 14.07.2020 14:15:17
- Zuletzt bearbeitet 21.11.2024 05:01:46
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbo...
CVE-2019-20907
- EPSS 0.29%
- Veröffentlicht 13.07.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 04:39:39
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
CVE-2020-12402
- EPSS 0.08%
- Veröffentlicht 09.07.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:59:38
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to re...
CVE-2020-15095
- EPSS 0.04%
- Veröffentlicht 07.07.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:04:47
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and...
CVE-2020-10745
- EPSS 16.33%
- Veröffentlicht 07.07.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:58
A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows a remote attacker could to cause the Samba server to consume excessive CPU use, resulting in a denia...
CVE-2020-10730
- EPSS 2.76%
- Veröffentlicht 07.07.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:55:56
A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17, before 4.11.11 and before 4.12.4. Although some versions of Samba shipped with Red Hat Enterprise Linux do not support Samba in ...
CVE-2020-15564
- EPSS 0.08%
- Veröffentlicht 07.07.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 05:05:44
An issue was discovered in Xen through 4.13.x, allowing Arm guest OS users to cause a hypervisor crash because of a missing alignment check in VCPUOP_register_vcpu_info. The hypercall VCPUOP_register_vcpu_info is used by a guest to register a shared ...
CVE-2020-15565
- EPSS 0.08%
- Veröffentlicht 07.07.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 05:05:45
An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of service or possibly gain privileges because of insufficient cache write-back under VT-d. When page tables are shared between IOMMU and C...
CVE-2020-15567
- EPSS 0.06%
- Veröffentlicht 07.07.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 05:05:45
An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic modification of a live EPT PTE. When mapping guest EPT (nested paging) tables, Xen would in some circum...