Show filters
4,245 Total Results
Displaying 631-640 of 4,245
Sort by:
Attacker Value
Unknown
CVE-2020-1934
Disclosure Date: April 01, 2020 (last updated February 21, 2025)
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
0
Attacker Value
Unknown
CVE-2020-6807
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
0
Attacker Value
Unknown
CVE-2020-6814
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
0
Attacker Value
Unknown
CVE-2020-6805
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
0
Attacker Value
Unknown
CVE-2020-6812
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. To resolve this issue, Firefox added a special case that renames devices containing the substring 'AirPods' to simply 'AirPods'. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
0
Attacker Value
Unknown
CVE-2020-6811
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
0
Attacker Value
Unknown
CVE-2020-6806
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
0
Attacker Value
Unknown
CVE-2020-10942
Disclosure Date: March 24, 2020 (last updated February 21, 2025)
In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.
0
Attacker Value
Unknown
CVE-2020-1950
Disclosure Date: March 23, 2020 (last updated February 21, 2025)
A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
0
Attacker Value
Unknown
CVE-2020-1951
Disclosure Date: March 23, 2020 (last updated February 21, 2025)
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
0