Show filters
252 Total Results
Displaying 41-50 of 252
Sort by:
Attacker Value
Unknown
CVE-2020-11866
Disclosure Date: May 11, 2020 (last updated February 21, 2025)
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.
0
Attacker Value
Unknown
CVE-2020-11863
Disclosure Date: May 11, 2020 (last updated November 08, 2023)
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 1 of 2).
0
Attacker Value
Unknown
CVE-2020-11865
Disclosure Date: May 11, 2020 (last updated February 21, 2025)
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access.
0
Attacker Value
Unknown
CVE-2020-12767
Disclosure Date: May 09, 2020 (last updated February 21, 2025)
exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error.
0
Attacker Value
Unknown
CVE-2020-10683
Disclosure Date: May 01, 2020 (last updated February 21, 2025)
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
0
Attacker Value
Unknown
CVE-2020-12050
Disclosure Date: April 30, 2020 (last updated February 21, 2025)
SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a /tmp/sqliteodbc$$ file with new contents that cause loading of an arbitrary library.
0
Attacker Value
Unknown
CVE-2020-10663
Disclosure Date: April 28, 2020 (last updated February 21, 2025)
The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.
0
Attacker Value
Unknown
CVE-2020-1983
Disclosure Date: April 20, 2020 (last updated February 21, 2025)
A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.
0
Attacker Value
Unknown
CVE-2020-6095
Disclosure Date: March 27, 2020 (last updated February 21, 2025)
An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2020-10531
Disclosure Date: March 12, 2020 (last updated February 21, 2025)
An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.
0