CVE-2020-12762
- EPSS 0.28%
- Veröffentlicht 09.05.2020 18:15:11
- Zuletzt bearbeitet 03.11.2025 20:15:44
json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
CVE-2020-12740
- EPSS 0.51%
- Veröffentlicht 08.05.2020 18:15:10
- Zuletzt bearbeitet 21.11.2024 05:00:10
tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c.
CVE-2020-11054
- EPSS 0.65%
- Veröffentlicht 07.05.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:41
In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificate error was overridden by the user, qutebrowser displays the URL as yellow (colors.statusbar.url.warn.fg). However, when the affec...
CVE-2020-12108
- EPSS 7.99%
- Veröffentlicht 06.05.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:15
/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
CVE-2020-10704
- EPSS 8.89%
- Veröffentlicht 06.05.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:55:53
A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of ser...
CVE-2020-12666
- EPSS 0.16%
- Veröffentlicht 05.05.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:00:01
macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL.
CVE-2020-11033
- EPSS 0.45%
- Veröffentlicht 05.05.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:38
In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of users when querying apirest.php/User. The response contains: - All api_tokens which can be used to do privileges escalat...
CVE-2020-11035
- EPSS 0.24%
- Veröffentlicht 05.05.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:38
In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values. This is fixed in version 9.4.6.
CVE-2020-10700
- EPSS 2.86%
- Veröffentlicht 04.05.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:52
A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with the 'ASQ' control. A malicious user in a samba AD could use this flaw to cause denial of service. This issue affects all samba versi...
CVE-2020-10933
- EPSS 0.44%
- Veröffentlicht 04.05.2020 15:15:13
- Zuletzt bearbeitet 21.11.2024 04:56:23
An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buffer, exception: false), the method resizes the buffer to fit the requested size, but no data is copied...