Show filters
736 Total Results
Displaying 151-160 of 736
Sort by:
Attacker Value
Unknown

CVE-2020-7042

Disclosure Date: February 27, 2020 (last updated February 21, 2025)
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).
Attacker Value
Unknown

CVE-2020-7043

Disclosure Date: February 27, 2020 (last updated February 21, 2025)
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.
Attacker Value
Unknown

CVE-2020-9274

Disclosure Date: February 26, 2020 (last updated February 21, 2025)
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member. This is related to init_aliases in diraliases.c.
Attacker Value
Unknown

CVE-2020-9369

Disclosure Date: February 24, 2020 (last updated February 21, 2025)
Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malformed parameters.
Attacker Value
Unknown

CVE-2020-9365

Disclosure Date: February 24, 2020 (last updated February 21, 2025)
An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c.
Attacker Value
Unknown

CVE-2020-8130

Disclosure Date: February 24, 2020 (last updated February 21, 2025)
There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.
Attacker Value
Unknown

CVE-2019-18182

Disclosure Date: February 24, 2020 (last updated February 21, 2025)
pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function. This can be exploited when unsigned databases are used. To exploit the vulnerability, the user must enable a non-default XferCommand and retrieve an attacker-controlled crafted database and package.
Attacker Value
Unknown

CVE-2019-18183

Disclosure Date: February 24, 2020 (last updated February 21, 2025)
pacman before 5.2 is vulnerable to arbitrary command injection in lib/libalpm/sync.c in the apply_deltas() function. This can be exploited when unsigned databases are used. To exploit the vulnerability, the user must enable the non-default delta feature and retrieve an attacker-controlled crafted database and delta file.
Attacker Value
Unknown

CVE-2019-20044

Disclosure Date: February 24, 2020 (last updated February 21, 2025)
In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH=/dir/with/module zmodload with a module that calls setuid().
Attacker Value
Unknown

CVE-2020-8813

Disclosure Date: February 22, 2020 (last updated February 21, 2025)
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.