CVE-2020-6434
- EPSS 1.49%
- Veröffentlicht 13.04.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:35:43
Use after free in devtools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6435
- EPSS 0.74%
- Veröffentlicht 13.04.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:35:43
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
CVE-2020-1759
- EPSS 0.41%
- Veröffentlicht 13.04.2020 13:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:19
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and pote...
CVE-2013-7488
- EPSS 1.01%
- Veröffentlicht 07.04.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 02:01:08
perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop via unexpected input.
CVE-2020-11612
- EPSS 4.68%
- Veröffentlicht 07.04.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 04:58:14
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free m...
CVE-2020-11501
- EPSS 11.49%
- Veröffentlicht 03.04.2020 13:15:13
- Zuletzt bearbeitet 21.11.2024 04:58:01
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value, and thus contributes...
CVE-2020-8835
- EPSS 24.75%
- Veröffentlicht 02.04.2020 18:15:18
- Zuletzt bearbeitet 21.11.2024 05:39:32
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5....
CVE-2020-11100
- EPSS 75.55%
- Veröffentlicht 02.04.2020 15:15:17
- Zuletzt bearbeitet 21.11.2024 04:56:47
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
CVE-2020-1927
- EPSS 11.3%
- Veröffentlicht 02.04.2020 00:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:37
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
CVE-2020-6096
- EPSS 4.2%
- Veröffentlicht 01.04.2020 22:15:18
- Zuletzt bearbeitet 21.11.2024 05:35:05
An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in ...