Show filters
649 Total Results
Displaying 201-210 of 649
Sort by:
Attacker Value
Unknown
CVE-2020-2026
Disclosure Date: June 10, 2020 (last updated February 21, 2025)
A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for code execution on the host. This issue affects: Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; Kata Containers 1.9 and earlier versions.
0
Attacker Value
Unknown
CVE-2020-2023
Disclosure Date: June 10, 2020 (last updated February 21, 2025)
Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can exploit this to gain code execution on the guest and masquerade as the kata-agent. This issue affects Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; and Kata Containers 1.9 and earlier versions.
0
Attacker Value
Unknown
CVE-2020-6937
Disclosure Date: May 29, 2020 (last updated November 27, 2024)
A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resource exhaustion.
0
Attacker Value
Unknown
CVE-2020-10719
Disclosure Date: May 26, 2020 (last updated February 21, 2025)
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.
0
Attacker Value
Unknown
CVE-2020-2024
Disclosure Date: May 19, 2020 (last updated February 21, 2025)
An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a malicious guest can trick the kata-runtime into unmounting any mount point on the host and all mount points underneath it, potentiality resulting in a host DoS.
0
Attacker Value
Unknown
CVE-2020-2025
Disclosure Date: May 19, 2020 (last updated February 21, 2025)
Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gain control of all subsequent guest VMs. Since Kata Containers uses the same VM image file with all VMMs, this issue may also affect QEMU and Firecracker based guests.
0
Attacker Value
Unknown
CVE-2020-12068
Disclosure Date: May 14, 2020 (last updated November 27, 2024)
An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.
0
Attacker Value
Unknown
CVE-2020-1714
Disclosure Date: May 13, 2020 (last updated February 21, 2025)
A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.
0
Attacker Value
Unknown
CVE-2020-1718
Disclosure Date: May 12, 2020 (last updated February 21, 2025)
A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the application.
0
Attacker Value
Unknown
CVE-2020-1724
Disclosure Date: May 11, 2020 (last updated February 21, 2025)
A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.
0