Количество 25 045
Количество 25 045
CVE-2020-8623
A flaw in native PKCS#11 code can lead to a remotely triggerable assertion failure in pk11.c
CVE-2020-8622
A truncated TSIG response can lead to an assertion failure
CVE-2020-8621
Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c
CVE-2020-8620
In BIND 9.15.6 -> 9.16.5 9.17.0 -> 9.17.3 An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure causing the server to exit.
CVE-2020-8619
A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
CVE-2020-8618
A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
CVE-2020-8597
CVE-2020-8565
Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 9
CVE-2020-8563
Secret leaks in logs for vSphere Provider kube-controller-manager
CVE-2020-8561
Webhook redirect in kube-apiserver
CVE-2020-8554
Kubernetes man in the middle using LoadBalancer or ExternalIPs
CVE-2020-8428
CVE-2020-8286
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
CVE-2020-8285
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
CVE-2020-8284
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port and this way potentially make curl extract information about services that are otherwise private and not disclosed for example doing port scanning and service banner extractions.
CVE-2020-8277
CVE-2020-8231
Due to use of a dangling pointer libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.
CVE-2020-8177
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.
CVE-2020-8174
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0 12.18.0 and < 14.4.0.
CVE-2020-8169
curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-8623 A flaw in native PKCS#11 code can lead to a remotely triggerable assertion failure in pk11.c | CVSS3: 7.5 | 6% Низкий | почти 6 лет назад | |
CVE-2020-8622 A truncated TSIG response can lead to an assertion failure | CVSS3: 6.5 | 6% Низкий | почти 6 лет назад | |
CVE-2020-8621 Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c | CVSS3: 7.5 | 3% Низкий | почти 6 лет назад | |
CVE-2020-8620 In BIND 9.15.6 -> 9.16.5 9.17.0 -> 9.17.3 An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure causing the server to exit. | CVSS3: 7.5 | 4% Низкий | почти 6 лет назад | |
CVE-2020-8619 A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer | CVSS3: 4.9 | 2% Низкий | почти 6 лет назад | |
CVE-2020-8618 A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer | CVSS3: 4.9 | 2% Низкий | почти 6 лет назад | |
CVSS3: 9.8 | 20% Средний | около 2 лет назад | ||
CVE-2020-8565 Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 9 | CVSS3: 5.5 | 1% Низкий | больше 1 года назад | |
CVE-2020-8563 Secret leaks in logs for vSphere Provider kube-controller-manager | CVSS3: 5.5 | 1% Низкий | больше 5 лет назад | |
CVE-2020-8561 Webhook redirect in kube-apiserver | CVSS3: 4.1 | 2% Низкий | 10 месяцев назад | |
CVE-2020-8554 Kubernetes man in the middle using LoadBalancer or ExternalIPs | CVSS3: 5 | 9% Низкий | 6 месяцев назад | |
CVSS3: 7.1 | 1% Низкий | почти 6 лет назад | ||
CVE-2020-8286 curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. | CVSS3: 7.5 | 5% Низкий | больше 5 лет назад | |
CVE-2020-8285 curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing. | CVSS3: 7.5 | 10% Низкий | больше 5 лет назад | |
CVE-2020-8284 A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port and this way potentially make curl extract information about services that are otherwise private and not disclosed for example doing port scanning and service banner extractions. | CVSS3: 3.7 | 4% Низкий | больше 5 лет назад | |
CVSS3: 7.5 | 54% Средний | больше 5 лет назад | ||
CVE-2020-8231 Due to use of a dangling pointer libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data. | CVSS3: 7.5 | 4% Низкий | больше 5 лет назад | |
CVE-2020-8177 curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used. | CVSS3: 7.8 | 1% Низкий | больше 5 лет назад | |
CVE-2020-8174 napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0 12.18.0 and < 14.4.0. | CVSS3: 8.1 | 8% Низкий | около 5 лет назад | |
CVE-2020-8169 curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s). | CVSS3: 7.5 | 3% Низкий | больше 5 лет назад |
Уязвимостей на страницу