- EPSS 0.03%
- Veröffentlicht 11.03.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:16
A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in ...
CVE-2020-9440
- EPSS 0.49%
- Veröffentlicht 10.03.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:40:38
A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML element into the editor.
CVE-2020-10232
- EPSS 1.41%
- Veröffentlicht 09.03.2020 00:15:10
- Zuletzt bearbeitet 21.11.2024 04:55:01
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c.
CVE-2020-9281
- EPSS 1.19%
- Veröffentlicht 07.03.2020 01:15:15
- Zuletzt bearbeitet 21.11.2024 05:40:20
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
- EPSS 8.4%
- Veröffentlicht 06.03.2020 15:15:14
- Zuletzt bearbeitet 21.01.2026 02:15:47
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
- EPSS 0.12%
- Veröffentlicht 05.03.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:54:54
init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the predictable location /tmp/timeshift. It follows symlinks in this location or uses directories owned by unprivileged users. Because T...
CVE-2020-9402
- EPSS 82.51%
- Veröffentlicht 05.03.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:40:33
Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggreg...
CVE-2020-10029
- EPSS 0.06%
- Veröffentlicht 04.03.2020 15:15:13
- Zuletzt bearbeitet 21.11.2024 04:54:40
The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl...
CVE-2020-10018
- EPSS 2.04%
- Veröffentlicht 02.03.2020 23:15:11
- Zuletzt bearbeitet 21.11.2024 04:54:39
WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed in 2.28.0 with improved memor...
CVE-2020-5247
- EPSS 2.09%
- Veröffentlicht 28.02.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:33:45
In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response header, an attacker can use newline characters (i.e. `CR`, `LF` or`/r`, `/n`) to end the header and inject malicious content, such as ...