CVE-2019-20386
- EPSS 0.15%
- Veröffentlicht 21.01.2020 06:15:11
- Zuletzt bearbeitet 09.06.2025 16:15:30
An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.
CVE-2020-7044
- EPSS 0.73%
- Veröffentlicht 16.01.2020 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:36:32
In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors.
CVE-2020-7105
- EPSS 0.57%
- Veröffentlicht 16.01.2020 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:36:38
async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.
CVE-2020-7106
- EPSS 4.09%
- Veröffentlicht 16.01.2020 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:36:38
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string fr...
CVE-2019-19547
- EPSS 1.07%
- Veröffentlicht 13.01.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:56
Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issue. XSS is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. An XSS vul...
CVE-2020-6860
- EPSS 0.54%
- Veröffentlicht 13.01.2020 07:15:10
- Zuletzt bearbeitet 21.11.2024 05:36:18
libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute.
CVE-2020-6851
- EPSS 1.22%
- Veröffentlicht 13.01.2020 06:15:10
- Zuletzt bearbeitet 21.11.2024 05:36:17
OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.
CVE-2020-6377
- EPSS 2.9%
- Veröffentlicht 10.01.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:36
Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-13767
- EPSS 7.42%
- Veröffentlicht 10.01.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 04:25:41
Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6750
- EPSS 0.59%
- Veröffentlicht 09.01.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:36:07
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur...