Show filters
2,155 Total Results
Displaying 141-150 of 2,155
Sort by:
Attacker Value
Unknown
CVE-2020-9383
Disclosure Date: February 25, 2020 (last updated February 21, 2025)
An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-2e90ca68b0d2.
0
Attacker Value
Unknown
CVE-2015-9542
Disclosure Date: February 24, 2020 (last updated February 21, 2025)
add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and crash it. Arbitrary code execution might be possible, depending on the application, C library, compiler, and other factors.
0
Attacker Value
Unknown
CVE-2011-4915
Disclosure Date: February 20, 2020 (last updated February 21, 2025)
fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.
0
Attacker Value
Unknown
CVE-2015-7747
Disclosure Date: February 19, 2020 (last updated February 21, 2025)
Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio file, as demonstrated by sixteen-stereo-to-eight-mono.c.
0
Attacker Value
Unknown
CVE-2020-7064
Disclosure Date: February 17, 2020 (last updated February 21, 2025)
In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data() function, it is possible for malicious data to cause PHP to read one byte of uninitialized memory. This could potentially lead to information disclosure or crash.
0
Attacker Value
Unknown
CVE-2020-7062
Disclosure Date: February 17, 2020 (last updated February 21, 2025)
In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set to 0 (disabled), and the file upload fails, the upload procedure would try to clean up data that does not exist and encounter null pointer dereference, which would likely lead to a crash.
0
Attacker Value
Unknown
CVE-2020-8992
Disclosure Date: February 14, 2020 (last updated February 21, 2025)
ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size.
0
Attacker Value
Unknown
CVE-2018-14553
Disclosure Date: February 11, 2020 (last updated February 21, 2025)
gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).
0
Attacker Value
Unknown
CVE-2020-8648
Disclosure Date: February 06, 2020 (last updated February 21, 2025)
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c.
0
Attacker Value
Unknown
CVE-2020-3123
Disclosure Date: February 05, 2020 (last updated February 21, 2025)
A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to an out-of-bounds read affecting users that have enabled the optional DLP feature. An attacker could exploit this vulnerability by sending a crafted email file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.
0