CVE-2020-10803
- EPSS 3.55%
- Veröffentlicht 22.03.2020 05:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:06
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Displa...
- EPSS 2.44%
- Veröffentlicht 22.03.2020 04:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:06
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the...
CVE-2020-8139
- EPSS 0.32%
- Veröffentlicht 20.03.2020 21:15:17
- Zuletzt bearbeitet 21.11.2024 05:38:22
A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.
CVE-2019-14855
- EPSS 0.4%
- Veröffentlicht 20.03.2020 16:15:14
- Zuletzt bearbeitet 21.11.2024 04:27:30
A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.
CVE-2020-5267
- EPSS 0.89%
- Veröffentlicht 19.03.2020 18:15:16
- Zuletzt bearbeitet 21.11.2024 05:33:48
In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks. The issue is fixed in...
CVE-2020-10675
- EPSS 0.28%
- Veröffentlicht 19.03.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:49
The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via a Delete call.
CVE-2019-20485
- EPSS 0.19%
- Veröffentlicht 19.03.2020 02:15:10
- Zuletzt bearbeitet 21.11.2024 04:38:35
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).
CVE-2020-7919
- EPSS 0.85%
- Veröffentlicht 16.03.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:00
Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.
CVE-2020-6581
- EPSS 0.27%
- Veröffentlicht 16.03.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:36:00
Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets \n as the character \ and the character n (not as the \n newline sequence). This can cause command injection.
CVE-2020-6582
- EPSS 1.65%
- Veröffentlicht 16.03.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:36:00
Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call.