- EPSS 0.54%
- Veröffentlicht 12.05.2020 13:15:13
- Zuletzt bearbeitet 21.11.2024 05:38:24
A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.
CVE-2020-8151
- EPSS 0.29%
- Veröffentlicht 12.05.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:23
There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information.
CVE-2020-8153
- EPSS 0.37%
- Veröffentlicht 12.05.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:23
Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name.
CVE-2018-1285
- EPSS 72.07%
- Veröffentlicht 11.05.2020 17:15:10
- Zuletzt bearbeitet 21.11.2024 03:59:32
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.
CVE-2020-11863
- EPSS 0.44%
- Veröffentlicht 11.05.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:58:46
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 1 of 2).
CVE-2020-11864
- EPSS 0.44%
- Veröffentlicht 11.05.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:58:46
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 2 of 2).
CVE-2020-11865
- EPSS 0.41%
- Veröffentlicht 11.05.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:58:46
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access.
CVE-2020-11866
- EPSS 0.41%
- Veröffentlicht 11.05.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:58:47
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.
CVE-2020-12783
- EPSS 3.19%
- Veröffentlicht 11.05.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:17
Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.
CVE-2020-12770
- EPSS 0.04%
- Veröffentlicht 09.05.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:15
An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failure case, aka CID-83c6f2390040.