Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 892

Количество 55 892

redhat логотип

CVE-2020-25284

почти 6 лет назад

The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map or unmap rbd block devices, aka CID-f44d04e696fe.

CVSS3: 4.1
EPSS: Низкий
redhat логотип

CVE-2020-25275

больше 5 лет назад

Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2020-25221

почти 6 лет назад

get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counting (caused by gate page mishandling) of the struct page that backs the vsyscall page. The result is a refcount underflow. This can be triggered by any 64-bit process that can use ptrace() or process_vm_readv(), aka CID-9fa2dd946743.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2020-25220

около 6 лет назад

The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because skcd->no_refcnt was not considered during a backport of a CVE-2020-14356 patch. This is related to the cgroups feature.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2020-25219

почти 6 лет назад

url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2020-25212

почти 6 лет назад

A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b4487b935452.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2020-25211

почти 6 лет назад

In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctnetlink_parse_tuple_filter in net/netfilter/nf_conntrack_netlink.c, aka CID-1cc5ef91d2ff.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2020-25125

почти 6 лет назад

GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified other impact, when a victim imports an attacker's OpenPGP key, and this key has AEAD preferences. The overflow is caused by a g10/key-check.c error. NOTE: GnuPG 2.3.x is unaffected. GnuPG 2.2.23 is a fixed version.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2020-25097

почти 6 лет назад

An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbidden by the security controls. This occurs for certain uri_whitespace configuration settings.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2020-25085

около 6 лет назад

QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case.

CVSS3: 5
EPSS: Низкий
redhat логотип

CVE-2020-25084

около 6 лет назад

QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked.

CVSS3: 3.2
EPSS: Низкий
redhat логотип

CVE-2020-25032

около 6 лет назад

An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2020-25018

почти 6 лет назад

Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2020-25017

почти 6 лет назад

Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy’s setCopy() header map API does not replace all existing occurences of a non-inline header.

CVSS3: 8.3
EPSS: Низкий
redhat логотип

CVE-2020-24980

почти 6 лет назад

[REJECTED CVE] An assertion failure flaw was found in GNU bison in src/parse-gram.c. A local attacker may execute bison with crafted input file containing character '\' at the end and while still in a character or a string.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-24979

почти 6 лет назад

[REJECTED CVE] A Buffer Overflow vulnerability was found in GNU bison in src/symtab.c. A local attacker may execute bison with crafted input file redefining the EOF token, which could triggers Heap buffer overflow and thus cause system crash.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-24978

почти 6 лет назад

In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-24977

почти 6 лет назад

GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2020-24890

около 6 лет назад

libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs only if you compile the software in a certain way

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2020-24889

около 6 лет назад

A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp may lead to context-dependent arbitrary code execution.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2020-25284

The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map or unmap rbd block devices, aka CID-f44d04e696fe.

CVSS3: 4.1
0%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-25275

Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.

CVSS3: 7.5
5%
Низкий
больше 5 лет назад
redhat логотип
CVE-2020-25221

get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counting (caused by gate page mishandling) of the struct page that backs the vsyscall page. The result is a refcount underflow. This can be triggered by any 64-bit process that can use ptrace() or process_vm_readv(), aka CID-9fa2dd946743.

CVSS3: 7.8
1%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-25220

The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because skcd->no_refcnt was not considered during a backport of a CVE-2020-14356 patch. This is related to the cgroups feature.

CVSS3: 7
0%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-25219

url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.

CVSS3: 5.9
4%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-25212

A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b4487b935452.

CVSS3: 7
0%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-25211

In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctnetlink_parse_tuple_filter in net/netfilter/nf_conntrack_netlink.c, aka CID-1cc5ef91d2ff.

CVSS3: 6.7
1%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-25125

GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified other impact, when a victim imports an attacker's OpenPGP key, and this key has AEAD preferences. The overflow is caused by a g10/key-check.c error. NOTE: GnuPG 2.3.x is unaffected. GnuPG 2.2.23 is a fixed version.

CVSS3: 7
1%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-25097

An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbidden by the security controls. This occurs for certain uri_whitespace configuration settings.

CVSS3: 8.6
8%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-25085

QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case.

CVSS3: 5
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-25084

QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked.

CVSS3: 3.2
0%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-25032

An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.

CVSS3: 7.5
4%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-25018

Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization.

CVSS3: 7.5
1%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-25017

Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy’s setCopy() header map API does not replace all existing occurences of a non-inline header.

CVSS3: 8.3
1%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-24980

[REJECTED CVE] An assertion failure flaw was found in GNU bison in src/parse-gram.c. A local attacker may execute bison with crafted input file containing character '\' at the end and while still in a character or a string.

CVSS3: 5.5
почти 6 лет назад
redhat логотип
CVE-2020-24979

[REJECTED CVE] A Buffer Overflow vulnerability was found in GNU bison in src/symtab.c. A local attacker may execute bison with crafted input file redefining the EOF token, which could triggers Heap buffer overflow and thus cause system crash.

CVSS3: 5.5
почти 6 лет назад
redhat логотип
CVE-2020-24978

In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.

CVSS3: 5.5
1%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-24977

GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.

CVSS3: 6.5
4%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-24890

libraw 20.0 has a null pointer dereference vulnerability in parse_tiff_ifd in src/metadata/tiff.cpp, which may result in context-dependent arbitrary code execution. Note: this vulnerability occurs only if you compile the software in a certain way

CVSS3: 5.3
2%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-24889

A buffer overflow vulnerability in LibRaw version < 20.0 LibRaw::GetNormalizedModel in src/metadata/normalize_model.cpp may lead to context-dependent arbitrary code execution.

CVSS3: 5.3
1%
Низкий
около 6 лет назад

Уязвимостей на страницу