Show filters
626 Total Results
Displaying 151-160 of 626
Sort by:
Attacker Value
Unknown

CVE-2020-14303

Disclosure Date: July 06, 2020 (last updated February 21, 2025)
A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash.
Attacker Value
Unknown

CVE-2017-18922

Disclosure Date: June 30, 2020 (last updated February 21, 2025)
It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.
Attacker Value
Unknown

CVE-2020-4067

Disclosure Date: June 29, 2020 (last updated February 21, 2025)
In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use their connection to intelligently query coturn to get interesting bytes in the padding bytes from the connection of another client. This has been fixed in 4.5.1.3.
Attacker Value
Unknown

CVE-2020-10753

Disclosure Date: June 26, 2020 (last updated February 21, 2025)
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.
Attacker Value
Unknown

CVE-2020-15305

Disclosure Date: June 26, 2020 (last updated February 21, 2025)
An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp.
Attacker Value
Unknown

CVE-2020-15306

Disclosure Date: June 26, 2020 (last updated February 21, 2025)
An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp.
Attacker Value
Unknown

CVE-2020-10177

Disclosure Date: June 25, 2020 (last updated February 21, 2025)
Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.
Attacker Value
Unknown

CVE-2020-10378

Disclosure Date: June 25, 2020 (last updated February 21, 2025)
In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer.
Attacker Value
Unknown

CVE-2020-10994

Disclosure Date: June 25, 2020 (last updated February 21, 2025)
In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.
Attacker Value
Unknown

CVE-2020-11538

Disclosure Date: June 25, 2020 (last updated February 21, 2025)
In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.