CVE-2020-14550
- EPSS 0.79%
- Veröffentlicht 15.07.2020 18:15:18
- Zuletzt bearbeitet 21.11.2024 05:03:31
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.48 and prior, 5.7.30 and prior and 8.0.20 and prior. Difficult to exploit vulnerability allows low privileged attacker with net...
CVE-2020-14553
- EPSS 0.36%
- Veröffentlicht 15.07.2020 18:15:18
- Zuletzt bearbeitet 21.11.2024 05:03:31
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with networ...
CVE-2020-14547
- EPSS 0.3%
- Veröffentlicht 15.07.2020 18:15:17
- Zuletzt bearbeitet 21.11.2024 05:03:30
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network ac...
CVE-2020-14539
- EPSS 0.89%
- Veröffentlicht 15.07.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:03:29
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.48 and prior, 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacke...
CVE-2020-14540
- EPSS 0.49%
- Veröffentlicht 15.07.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:03:29
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access v...
- EPSS 1.22%
- Veröffentlicht 14.07.2020 14:15:17
- Zuletzt bearbeitet 21.11.2024 05:01:46
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbo...
CVE-2019-20907
- EPSS 0.32%
- Veröffentlicht 13.07.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 04:39:39
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
CVE-2020-12402
- EPSS 0.1%
- Veröffentlicht 09.07.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:59:38
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to re...
CVE-2020-15095
- EPSS 0.1%
- Veröffentlicht 07.07.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:04:47
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and...
CVE-2020-10745
- EPSS 16.33%
- Veröffentlicht 07.07.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:58
A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows a remote attacker could to cause the Samba server to consume excessive CPU use, resulting in a denia...