CVE-2020-3350
- EPSS 0.14%
- Veröffentlicht 18.06.2020 03:15:14
- Zuletzt bearbeitet 21.11.2024 05:30:51
A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability is due to a race condition th...
CVE-2020-8619
- EPSS 6.93%
- Veröffentlicht 17.06.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:39:08
In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone ...
CVE-2020-14040
- EPSS 0.01%
- Veröffentlicht 17.06.2020 20:15:09
- Zuletzt bearbeitet 21.11.2024 05:02:25
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 deco...
CVE-2020-14295
- EPSS 81.2%
- Veröffentlicht 17.06.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:02:56
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.
CVE-2020-14148
- EPSS 1.82%
- Veröffentlicht 15.06.2020 18:15:15
- Zuletzt bearbeitet 21.11.2024 05:02:44
The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function.
CVE-2020-13999
- EPSS 0.33%
- Veröffentlicht 15.06.2020 16:15:22
- Zuletzt bearbeitet 21.11.2024 05:02:19
ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer overflow and denial of service via a crafted EMF file.
CVE-2020-0543
- EPSS 0.48%
- Veröffentlicht 15.06.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:53:42
Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2020-4046
- EPSS 6.85%
- Veröffentlicht 12.06.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:32:12
In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a higher privileged user, this coul...
CVE-2020-4047
- EPSS 5.57%
- Veröffentlicht 12.06.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:32:13
In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privilege...
CVE-2020-4048
- EPSS 3.5%
- Veröffentlicht 12.06.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:32:13
In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in version 5.4.2, along with all the ...