- EPSS 52.27%
- Veröffentlicht 20.02.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:40:19
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
CVE-2020-9308
- EPSS 0.73%
- Veröffentlicht 20.02.2020 07:15:12
- Zuletzt bearbeitet 21.11.2024 05:40:23
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact.
CVE-2019-20479
- EPSS 0.47%
- Veröffentlicht 20.02.2020 06:15:11
- Zuletzt bearbeitet 21.11.2024 04:38:34
A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.
CVE-2015-7747
- EPSS 57.37%
- Veröffentlicht 19.02.2020 21:15:11
- Zuletzt bearbeitet 13.08.2025 20:48:07
Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio file, as dem...
CVE-2020-6061
- EPSS 1.77%
- Veröffentlicht 19.02.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:00
An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS reque...
CVE-2020-6062
- EPSS 8.33%
- Veröffentlicht 19.02.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:00
An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to send an HTTP request to trigge...
CVE-2019-20477
- EPSS 0.46%
- Veröffentlicht 19.02.2020 04:15:10
- Zuletzt bearbeitet 21.11.2024 04:38:34
PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-183...
CVE-2014-8089
- EPSS 1.12%
- Veröffentlicht 17.02.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 02:18:31
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
CVE-2020-8518
- EPSS 84.86%
- Veröffentlicht 17.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:38:59
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
CVE-2019-20454
- EPSS 0.12%
- Veröffentlicht 14.02.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:38:31
An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which woul...