CVE-2020-8835
- EPSS 23.27%
- Veröffentlicht 02.04.2020 18:15:18
- Zuletzt bearbeitet 21.11.2024 05:39:32
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5....
CVE-2020-11100
- EPSS 74.79%
- Veröffentlicht 02.04.2020 15:15:17
- Zuletzt bearbeitet 21.11.2024 04:56:47
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
CVE-2020-1927
- EPSS 6.56%
- Veröffentlicht 02.04.2020 00:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:37
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
CVE-2020-6096
- EPSS 4.49%
- Veröffentlicht 01.04.2020 22:15:18
- Zuletzt bearbeitet 21.11.2024 05:35:05
An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in ...
CVE-2020-1934
- EPSS 27.24%
- Veröffentlicht 01.04.2020 20:15:15
- Zuletzt bearbeitet 21.11.2024 05:11:38
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
CVE-2019-14905
- EPSS 0.09%
- Veröffentlicht 31.03.2020 17:15:26
- Zuletzt bearbeitet 21.11.2024 04:27:39
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code c...
CVE-2020-8551
- EPSS 0.45%
- Veröffentlicht 27.03.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:39:01
The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and ...
CVE-2020-8552
- EPSS 0.07%
- Veröffentlicht 27.03.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:39:01
The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
CVE-2020-6802
- EPSS 0.27%
- Veröffentlicht 24.03.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:36:12
In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option.
CVE-2020-6816
- EPSS 0.42%
- Veröffentlicht 24.03.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:36:13
In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.