Количество 18 769
Количество 18 769
CVE-2020-8623
A flaw in native PKCS#11 code can lead to a remotely triggerable assertion failure in pk11.c
CVE-2020-8622
A truncated TSIG response can lead to an assertion failure
CVE-2020-8621
Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c
CVE-2020-8620
In BIND 9.15.6 -> 9.16.5 9.17.0 -> 9.17.3 An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure causing the server to exit.
CVE-2020-8619
A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
CVE-2020-8618
A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
CVE-2020-8597
CVE-2020-8565
CVE-2020-8563
Secret leaks in logs for vSphere Provider kube-controller-manager
CVE-2020-8561
Webhook redirect in kube-apiserver
CVE-2020-8554
CVE-2020-8428
CVE-2020-8286
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
CVE-2020-8285
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
CVE-2020-8284
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port and this way potentially make curl extract information about services that are otherwise private and not disclosed for example doing port scanning and service banner extractions.
CVE-2020-8277
CVE-2020-8231
Due to use of a dangling pointer libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.
CVE-2020-8177
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.
CVE-2020-8174
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0 12.18.0 and < 14.4.0.
CVE-2020-8169
curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-8623 A flaw in native PKCS#11 code can lead to a remotely triggerable assertion failure in pk11.c | CVSS3: 7.5 | 18% Средний | больше 5 лет назад | |
CVE-2020-8622 A truncated TSIG response can lead to an assertion failure | CVSS3: 6.5 | 2% Низкий | больше 5 лет назад | |
CVE-2020-8621 Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c | CVSS3: 7.5 | 4% Низкий | больше 5 лет назад | |
CVE-2020-8620 In BIND 9.15.6 -> 9.16.5 9.17.0 -> 9.17.3 An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure causing the server to exit. | CVSS3: 7.5 | 7% Низкий | больше 5 лет назад | |
CVE-2020-8619 A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer | CVSS3: 4.9 | 7% Низкий | больше 5 лет назад | |
CVE-2020-8618 A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer | CVSS3: 4.9 | 1% Низкий | больше 5 лет назад | |
CVSS3: 9.8 | 64% Средний | больше 1 года назад | ||
CVSS3: 5.5 | 0% Низкий | 11 месяцев назад | ||
CVE-2020-8563 Secret leaks in logs for vSphere Provider kube-controller-manager | CVSS3: 5.5 | 0% Низкий | около 5 лет назад | |
CVE-2020-8561 Webhook redirect in kube-apiserver | CVSS3: 4.1 | 0% Низкий | 4 месяца назад | |
CVSS3: 5 | 30% Средний | больше 2 лет назад | ||
CVSS3: 7.1 | 0% Низкий | больше 5 лет назад | ||
CVE-2020-8286 curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. | CVSS3: 7.5 | 0% Низкий | около 5 лет назад | |
CVE-2020-8285 curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing. | CVSS3: 7.5 | 1% Низкий | около 5 лет назад | |
CVE-2020-8284 A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port and this way potentially make curl extract information about services that are otherwise private and not disclosed for example doing port scanning and service banner extractions. | CVSS3: 3.7 | 0% Низкий | около 5 лет назад | |
CVSS3: 7.5 | 59% Средний | почти 5 лет назад | ||
CVE-2020-8231 Due to use of a dangling pointer libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data. | CVSS3: 7.5 | 0% Низкий | около 5 лет назад | |
CVE-2020-8177 curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used. | CVSS3: 7.8 | 0% Низкий | около 5 лет назад | |
CVE-2020-8174 napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0 12.18.0 and < 14.4.0. | CVSS3: 8.1 | 2% Низкий | больше 4 лет назад | |
CVE-2020-8169 curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s). | CVSS3: 7.5 | 0% Низкий | около 5 лет назад |
Уязвимостей на страницу