Количество 25 045
Количество 25 045
CVE-2020-1379
Media Foundation Memory Corruption Vulnerability
CVE-2020-13791
hw/pci/pci.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access by providing an address near the end of the PCI configuration space.
CVE-2020-1378
Windows Registry Elevation of Privilege Vulnerability
CVE-2020-1377
Windows Registry Elevation of Privilege Vulnerability
CVE-2020-13777
GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2 and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation the TLS server always uses wrong data in place of an encryption key derived from an application.
CVE-2020-13776
systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000082.
CVE-2020-1376
Windows Elevation of Privilege Vulnerability
CVE-2020-1375
Windows COM Server Elevation of Privilege Vulnerability
CVE-2020-13754
hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.
CVE-2020-1374
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2020-1373
Windows Network Connections Service Elevation of Privilege Vulnerability
CVE-2020-1372
Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability
CVE-2020-1371
Windows Event Logging Service Elevation of Privilege Vulnerability
CVE-2020-1370
Windows Runtime Elevation of Privilege Vulnerability
CVE-2020-1369
Windows WalletService Elevation of Privilege Vulnerability
CVE-2020-1368
Windows Credential Enrollment Manager Service Elevation of Privilege Vulnerability
CVE-2020-1367
Windows Kernel Information Disclosure Vulnerability
CVE-2020-1366
Windows Print Workflow Service Elevation of Privilege Vulnerability
CVE-2020-1365
Windows Event Logging Service Elevation of Privilege Vulnerability
CVE-2020-13659
address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-1379 Media Foundation Memory Corruption Vulnerability | CVSS3: 7.8 | 3% Низкий | почти 6 лет назад | |
CVE-2020-13791 hw/pci/pci.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access by providing an address near the end of the PCI configuration space. | CVSS3: 5.5 | 0% Низкий | почти 6 лет назад | |
CVE-2020-1378 Windows Registry Elevation of Privilege Vulnerability | CVSS3: 7.8 | 4% Низкий | почти 6 лет назад | |
CVE-2020-1377 Windows Registry Elevation of Privilege Vulnerability | CVSS3: 7.8 | 2% Низкий | почти 6 лет назад | |
CVE-2020-13777 GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2 and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation the TLS server always uses wrong data in place of an encryption key derived from an application. | CVSS3: 7.4 | 18% Средний | почти 6 лет назад | |
CVE-2020-13776 systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000082. | CVSS3: 6.7 | 0% Низкий | почти 6 лет назад | |
CVE-2020-1376 Windows Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | почти 6 лет назад | |
CVE-2020-1375 Windows COM Server Elevation of Privilege Vulnerability | CVSS3: 7.8 | 7% Низкий | около 6 лет назад | |
CVE-2020-13754 hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation. | CVSS3: 6.7 | 0% Низкий | почти 6 лет назад | |
CVE-2020-1374 Remote Desktop Client Remote Code Execution Vulnerability | CVSS3: 7.5 | 8% Низкий | около 6 лет назад | |
CVE-2020-1373 Windows Network Connections Service Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | около 6 лет назад | |
CVE-2020-1372 Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | около 6 лет назад | |
CVE-2020-1371 Windows Event Logging Service Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | около 6 лет назад | |
CVE-2020-1370 Windows Runtime Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | около 6 лет назад | |
CVE-2020-1369 Windows WalletService Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | около 6 лет назад | |
CVE-2020-1368 Windows Credential Enrollment Manager Service Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | около 6 лет назад | |
CVE-2020-1367 Windows Kernel Information Disclosure Vulnerability | CVSS3: 5.5 | 1% Низкий | около 6 лет назад | |
CVE-2020-1366 Windows Print Workflow Service Elevation of Privilege Vulnerability | CVSS3: 7 | 1% Низкий | около 6 лет назад | |
CVE-2020-1365 Windows Event Logging Service Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | около 6 лет назад | |
CVE-2020-13659 address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer. | CVSS3: 2.5 | 0% Низкий | почти 6 лет назад |
Уязвимостей на страницу