Количество 18 769
Количество 18 769
CVE-2020-1083
Microsoft Graphics Component Information Disclosure Vulnerability
CVE-2020-1082
Windows Error Reporting Elevation of Privilege Vulnerability
CVE-2020-1081
Windows Printer Service Elevation of Privilege Vulnerability
CVE-2020-1080
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2020-1079
Microsoft Windows Elevation of Privilege Vulnerability
CVE-2020-1078
Windows Installer Elevation of Privilege Vulnerability
CVE-2020-10781
A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module where a user with a local account and the ability to read the /sys/class/zram-control/hot_add file can create ZRAM device nodes in the /dev/ directory. This read allocates kernel memory and is not accounted for a user that triggers the creation of that ZRAM device. With this vulnerability continually reading the device may consume a large amount of system memory and cause the Out-of-Memory (OOM) killer to activate and terminate random userspace processes possibly making the system inoperable.
CVE-2020-1077
Windows Runtime Elevation of Privilege Vulnerability
CVE-2020-1076
Windows Denial of Service Vulnerability
CVE-2020-10768
A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function where it can be used to enable indirect branch speculation after it has been disabled. This call incorrectly reports it as being 'force disabled' when it is not and opens the system to Spectre v2 attacks. The highest threat from this vulnerability is to confidentiality.
CVE-2020-10767
A flaw was found in the Linux kernel before 5.8-rc1 in the implementation of the Enhanced IBPB (Indirect Branch Prediction Barrier). The IBPB mitigation will be disabled when STIBP is not available or when the Enhanced Indirect Branch Restricted Speculation (IBRS) is available. This flaw allows a local attacker to perform a Spectre V2 style attack when this configuration is active. The highest threat from this vulnerability is to confidentiality.
CVE-2020-10766
A logic bug flaw was found in Linux kernel before 5.8-rc1 in the implementation of SSBD. A bug in the logic handling allows an attacker with a local account to disable SSBD protection during a context switch when additional speculative execution mitigations are in place. This issue was introduced when the per task/process conditional STIPB switching was added on top of the existing SSBD switching. The highest threat from this vulnerability is to confidentiality.
CVE-2020-10761
An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service.
CVE-2020-1075
Windows Subsystem for Linux Information Disclosure Vulnerability
CVE-2020-10757
CVE-2020-1074
Jet Database Engine Remote Code Execution Vulnerability
CVE-2020-10744
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18 2.8.12 and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5 3.5.6 and 3.6.4 as well as previous versions are affected.
CVE-2020-1073
Scripting Engine Memory Corruption Vulnerability
CVE-2020-10735
CVE-2020-10733
The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-1083 Microsoft Graphics Component Information Disclosure Vulnerability | CVSS3: 5.5 | 1% Низкий | больше 5 лет назад | |
CVE-2020-1082 Windows Error Reporting Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | больше 5 лет назад | |
CVE-2020-1081 Windows Printer Service Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | больше 5 лет назад | |
CVE-2020-1080 Windows Hyper-V Elevation of Privilege Vulnerability | CVSS3: 8.8 | 1% Низкий | больше 5 лет назад | |
CVE-2020-1079 Microsoft Windows Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | больше 5 лет назад | |
CVE-2020-1078 Windows Installer Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | больше 5 лет назад | |
CVE-2020-10781 A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module where a user with a local account and the ability to read the /sys/class/zram-control/hot_add file can create ZRAM device nodes in the /dev/ directory. This read allocates kernel memory and is not accounted for a user that triggers the creation of that ZRAM device. With this vulnerability continually reading the device may consume a large amount of system memory and cause the Out-of-Memory (OOM) killer to activate and terminate random userspace processes possibly making the system inoperable. | CVSS3: 5.5 | 0% Низкий | больше 5 лет назад | |
CVE-2020-1077 Windows Runtime Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | больше 5 лет назад | |
CVE-2020-1076 Windows Denial of Service Vulnerability | CVSS3: 5.5 | 0% Низкий | больше 5 лет назад | |
CVE-2020-10768 A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function where it can be used to enable indirect branch speculation after it has been disabled. This call incorrectly reports it as being 'force disabled' when it is not and opens the system to Spectre v2 attacks. The highest threat from this vulnerability is to confidentiality. | CVSS3: 5.5 | 0% Низкий | больше 5 лет назад | |
CVE-2020-10767 A flaw was found in the Linux kernel before 5.8-rc1 in the implementation of the Enhanced IBPB (Indirect Branch Prediction Barrier). The IBPB mitigation will be disabled when STIBP is not available or when the Enhanced Indirect Branch Restricted Speculation (IBRS) is available. This flaw allows a local attacker to perform a Spectre V2 style attack when this configuration is active. The highest threat from this vulnerability is to confidentiality. | CVSS3: 5.5 | 0% Низкий | больше 5 лет назад | |
CVE-2020-10766 A logic bug flaw was found in Linux kernel before 5.8-rc1 in the implementation of SSBD. A bug in the logic handling allows an attacker with a local account to disable SSBD protection during a context switch when additional speculative execution mitigations are in place. This issue was introduced when the per task/process conditional STIPB switching was added on top of the existing SSBD switching. The highest threat from this vulnerability is to confidentiality. | CVSS3: 5.5 | 0% Низкий | больше 5 лет назад | |
CVE-2020-10761 An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server resulting in a denial of service. | CVSS3: 5 | 1% Низкий | больше 5 лет назад | |
CVE-2020-1075 Windows Subsystem for Linux Information Disclosure Vulnerability | CVSS3: 5.5 | 0% Низкий | больше 5 лет назад | |
CVSS3: 7.8 | 1% Низкий | больше 5 лет назад | ||
CVE-2020-1074 Jet Database Engine Remote Code Execution Vulnerability | CVSS3: 7.8 | 31% Средний | больше 5 лет назад | |
CVE-2020-10744 An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18 2.8.12 and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5 3.5.6 and 3.6.4 as well as previous versions are affected. | CVSS3: 5 | 0% Низкий | больше 5 лет назад | |
CVE-2020-1073 Scripting Engine Memory Corruption Vulnerability | CVSS3: 4.2 | 14% Средний | больше 5 лет назад | |
CVSS3: 7.5 | 0% Низкий | около 3 лет назад | ||
CVE-2020-10733 The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. | CVSS3: 7.3 | 0% Низкий | больше 5 лет назад |
Уязвимостей на страницу