Show filters
736 Total Results
Displaying 161-170 of 736
Sort by:
Attacker Value
Unknown
CVE-2020-9273
Disclosure Date: February 20, 2020 (last updated February 21, 2025)
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
0
Attacker Value
Unknown
CVE-2020-6062
Disclosure Date: February 19, 2020 (last updated February 21, 2025)
An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to send an HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2020-6061
Disclosure Date: February 19, 2020 (last updated February 21, 2025)
An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2019-20477
Disclosure Date: February 19, 2020 (last updated February 21, 2025)
PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.
0
Attacker Value
Unknown
CVE-2020-8518
Disclosure Date: February 17, 2020 (last updated February 21, 2025)
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
0
Attacker Value
Unknown
CVE-2020-8955
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malformed IRC message 324 (channel mode).
0
Attacker Value
Unknown
CVE-2020-8945
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.
0
Attacker Value
Unknown
CVE-2020-7046
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.
0
Attacker Value
Unknown
CVE-2020-7957
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet and a trailing > character exists. This causes a denial of service in which the recipient cannot read all of their messages.
0
Attacker Value
Unknown
CVE-2020-6396
Disclosure Date: February 11, 2020 (last updated November 08, 2023)
Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
0