Show filters
4,171 Total Results
Displaying 241-250 of 4,171
Sort by:
Attacker Value
Unknown

CVE-2020-8622

Disclosure Date: August 21, 2020 (last updated February 22, 2025)
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an assertion failure, causing the server to exit. Alternately, an off-path attacker would have to correctly guess when a TSIG-signed request was sent, along with other characteristics of the packet and message, and spoof a truncated response to trigger an assertion failure, causing the server to exit.
Attacker Value
Unknown

CVE-2020-15861

Disclosure Date: August 20, 2020 (last updated February 22, 2025)
Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.
Attacker Value
Unknown

CVE-2020-15862

Disclosure Date: August 20, 2020 (last updated February 22, 2025)
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
Attacker Value
Unknown

CVE-2020-14356

Disclosure Date: August 19, 2020 (last updated February 22, 2025)
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
Attacker Value
Unknown

CVE-2020-24394

Disclosure Date: August 19, 2020 (last updated February 22, 2025)
In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs because the current umask is not considered.
Attacker Value
Unknown

CVE-2020-16296

Disclosure Date: August 13, 2020 (last updated February 21, 2025)
A buffer overflow vulnerability in GetNumWrongData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Attacker Value
Unknown

CVE-2020-16291

Disclosure Date: August 13, 2020 (last updated February 21, 2025)
A buffer overflow vulnerability in contrib/gdevdj9.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Attacker Value
Unknown

CVE-2020-16295

Disclosure Date: August 13, 2020 (last updated February 21, 2025)
A null pointer dereference vulnerability in clj_media_size() in devices/gdevclj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Attacker Value
Unknown

CVE-2020-16289

Disclosure Date: August 13, 2020 (last updated February 21, 2025)
A buffer overflow vulnerability in cif_print_page() in devices/gdevcif.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Attacker Value
Unknown

CVE-2020-16310

Disclosure Date: August 13, 2020 (last updated February 21, 2025)
A division by zero vulnerability in dot24_print_page() in devices/gdevdm24.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.