CVE-2020-13596
- EPSS 0.99%
- Veröffentlicht 03.06.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:34
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.
CVE-2020-13776
- EPSS 0.13%
- Veröffentlicht 03.06.2020 03:15:10
- Zuletzt bearbeitet 09.06.2025 16:15:31
systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because...
CVE-2020-13775
- EPSS 0.97%
- Veröffentlicht 02.06.2020 23:15:10
- Zuletzt bearbeitet 21.11.2024 05:01:50
ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) if echo-message is not enabled and there is no network.
- EPSS 12.87%
- Veröffentlicht 02.06.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:01:11
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial o...
CVE-2020-13757
- EPSS 0.08%
- Veröffentlicht 01.06.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:01:47
Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted cipherte...
CVE-2020-12867
- EPSS 0.13%
- Veröffentlicht 01.06.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:00:27
A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.
CVE-2020-13645
- EPSS 0.61%
- Veröffentlicht 28.05.2020 12:15:11
- Zuletzt bearbeitet 21.11.2024 05:01:40
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended docu...
CVE-2020-10936
- EPSS 0.11%
- Veröffentlicht 27.05.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:24
Sympa before 6.2.56 allows privilege escalation.
CVE-2020-13632
- EPSS 0.03%
- Veröffentlicht 27.05.2020 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:01:38
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
- EPSS 0.08%
- Veröffentlicht 27.05.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:38
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.