Show filters
736 Total Results
Displaying 191-200 of 736
Sort by:
Attacker Value
Unknown

CVE-2020-6400

Disclosure Date: February 11, 2020 (last updated February 21, 2025)
Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Attacker Value
Unknown

CVE-2019-15605

Disclosure Date: February 07, 2020 (last updated February 21, 2025)
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
Attacker Value
Unknown

CVE-2020-5208

Disclosure Date: February 05, 2020 (last updated February 21, 2025)
It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especially dangerous if ipmitool is run as a privileged user. This problem is fixed in version 1.8.19.
Attacker Value
Unknown

CVE-2019-12528

Disclosure Date: February 04, 2020 (last updated November 08, 2023)
An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes.
Attacker Value
Unknown

CVE-2020-8450

Disclosure Date: February 04, 2020 (last updated February 21, 2025)
An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.
Attacker Value
Unknown

CVE-2020-8449

Disclosure Date: February 04, 2020 (last updated February 21, 2025)
An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters.
Attacker Value
Unknown

CVE-2019-20446

Disclosure Date: February 02, 2020 (last updated February 21, 2025)
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.
Attacker Value
Unknown

CVE-2020-7595

Disclosure Date: January 21, 2020 (last updated February 21, 2025)
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
Attacker Value
Unknown

CVE-2019-20386

Disclosure Date: January 21, 2020 (last updated February 21, 2025)
An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.
Attacker Value
Unknown

CVE-2020-7105

Disclosure Date: January 16, 2020 (last updated February 21, 2025)
async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.