CVE-2020-11741
- EPSS 0.11%
- Veröffentlicht 14.04.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 04:58:31
An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information about other guests, cause a denial of service, or possibly gain privileges. For guests for which "active" profi...
CVE-2020-11742
- EPSS 0.09%
- Veröffentlicht 14.04.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 04:58:31
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service because of bad continuation handling in GNTTABOP_copy. Grant table operations are expected to return 0 for success, and a negative number for errors. ...
CVE-2020-11743
- EPSS 0.09%
- Veröffentlicht 14.04.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 04:58:31
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service because of a bad error path in GNTTABOP_map_grant. Grant table operations are expected to return 0 for success, and a negative number for errors. Some...
CVE-2020-1730
- EPSS 0.08%
- Veröffentlicht 13.04.2020 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:15
A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup th...
CVE-2020-6455
- EPSS 1.23%
- Veröffentlicht 13.04.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:35:45
Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6456
- EPSS 0.61%
- Veröffentlicht 13.04.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:35:45
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker to bypass site isolation via crafted clipboard contents.
CVE-2020-6436
- EPSS 1.49%
- Veröffentlicht 13.04.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:43
Use after free in window management in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6437
- EPSS 0.92%
- Veröffentlicht 13.04.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:43
Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted application.
CVE-2020-6438
- EPSS 0.69%
- Veröffentlicht 13.04.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:43
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extens...
CVE-2020-6439
- EPSS 0.88%
- Veröffentlicht 13.04.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:43
Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page.