Количество 18 769
Количество 18 769
CVE-2020-28374
In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7 insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request aka CID-2896c93811e3. For example an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.
CVE-2020-28367
CVE-2020-28366
CVE-2020-28362
CVE-2020-28200
The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption as demonstrated by a situation with a complex regular expression for the regex extension.
CVE-2020-28196
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.
CVE-2020-28163
libdwarf before 20201201 allows a dwarf_print_lines.c NULL pointer dereference and application crash via a DWARF5 line-table header that has an invalid FORM for a pathname.
CVE-2020-27845
CVE-2020-27844
Chromium CVE-2020-27844: Heap buffer overflow in OpenJPEG
CVE-2020-27843
CVE-2020-27842
CVE-2020-27841
CVE-2020-27840
CVE-2020-27827
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
CVE-2020-27824
CVE-2020-27823
CVE-2020-27821
A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host resulting in a denial of service. This flaw affects QEMU versions prior to 5.2.0.
CVE-2020-27815
CVE-2020-27814
CVE-2020-27783
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-28374 In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7 insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request aka CID-2896c93811e3. For example an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore. | CVSS3: 8.1 | 0% Низкий | около 5 лет назад | |
CVSS3: 7.5 | 0% Низкий | около 5 лет назад | ||
CVSS3: 7.5 | 0% Низкий | около 5 лет назад | ||
CVSS3: 7.5 | 0% Низкий | около 5 лет назад | ||
CVE-2020-28200 The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption as demonstrated by a situation with a complex regular expression for the regex extension. | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
CVE-2020-28196 MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit. | CVSS3: 7.5 | 0% Низкий | больше 4 лет назад | |
CVE-2020-28163 libdwarf before 20201201 allows a dwarf_print_lines.c NULL pointer dereference and application crash via a DWARF5 line-table header that has an invalid FORM for a pathname. | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
CVSS3: 5.5 | 0% Низкий | больше 1 года назад | ||
CVE-2020-27844 Chromium CVE-2020-27844: Heap buffer overflow in OpenJPEG | 1% Низкий | почти 5 лет назад | ||
CVSS3: 5.5 | 0% Низкий | больше 1 года назад | ||
CVSS3: 5.5 | 0% Низкий | больше 1 года назад | ||
CVSS3: 5.5 | 0% Низкий | больше 1 года назад | ||
CVSS3: 7.5 | 18% Средний | больше 1 года назад | ||
CVE-2020-27827 A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs potentially causing a denial of service. The highest threat from this vulnerability is to system availability. | CVSS3: 7.5 | 0% Низкий | почти 5 лет назад | |
CVSS3: 5.5 | 0% Низкий | больше 1 года назад | ||
CVSS3: 7.8 | 0% Низкий | больше 1 года назад | ||
CVE-2020-27821 A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host resulting in a denial of service. This flaw affects QEMU versions prior to 5.2.0. | CVSS3: 6 | 0% Низкий | около 5 лет назад | |
CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | ||
CVSS3: 7.8 | 0% Низкий | больше 1 года назад | ||
CVSS3: 6.1 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу