Show filters
496 Total Results
Displaying 41-50 of 496
Sort by:
Attacker Value
Unknown
CVE-2020-25624
Disclosure Date: November 30, 2020 (last updated February 22, 2025)
hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver.
0
Attacker Value
Unknown
CVE-2020-25625
Disclosure Date: September 25, 2020 (last updated February 22, 2025)
hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop.
0
Attacker Value
Unknown
CVE-2020-25085
Disclosure Date: September 25, 2020 (last updated February 22, 2025)
QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case.
0
Attacker Value
Unknown
CVE-2020-25084
Disclosure Date: September 25, 2020 (last updated February 22, 2025)
QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked.
0
Attacker Value
Unknown
CVE-2020-15803
Disclosure Date: July 17, 2020 (last updated February 21, 2025)
Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.
0
Attacker Value
Unknown
CVE-2020-1735
Disclosure Date: March 16, 2020 (last updated February 21, 2025)
A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
0
Attacker Value
Unknown
CVE-2020-1740
Disclosure Date: March 16, 2020 (last updated February 21, 2025)
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing secret in the file. This method will delete the file before recreating it insecurely. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
0
Attacker Value
Unknown
CVE-2020-1739
Disclosure Date: March 12, 2020 (last updated February 21, 2025)
A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.
0
Attacker Value
Unknown
CVE-2020-1733
Disclosure Date: March 11, 2020 (last updated February 21, 2025)
A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 && mkdir -p <dir>"; this operation does not fail if the directory already exists and is owned by another user. An attacker could take advantage to gain control of the become user as the target directory can be retrieved by iterating '/proc/<pid>/cmdline'.
0
Attacker Value
Unknown
CVE-2015-0294
Disclosure Date: January 27, 2020 (last updated February 21, 2025)
GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
0