Show filters
811 Total Results
Displaying 71-80 of 811
Sort by:
Attacker Value
Unknown
CVE-2020-13753
Disclosure Date: July 14, 2020 (last updated February 21, 2025)
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling terminal's input buffer, similar to CVE-2017-5226.
0
Attacker Value
Unknown
CVE-2019-20907
Disclosure Date: July 13, 2020 (last updated February 21, 2025)
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
0
Attacker Value
Unknown
CVE-2020-10756
Disclosure Date: July 09, 2020 (last updated February 21, 2025)
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.
0
Attacker Value
Unknown
CVE-2020-12417
Disclosure Date: July 09, 2020 (last updated February 21, 2025)
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
0
Attacker Value
Unknown
CVE-2020-12418
Disclosure Date: July 09, 2020 (last updated February 21, 2025)
Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
0
Attacker Value
Unknown
CVE-2020-12419
Disclosure Date: July 09, 2020 (last updated February 21, 2025)
When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free condition. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
0
Attacker Value
Unknown
CVE-2020-12420
Disclosure Date: July 09, 2020 (last updated February 21, 2025)
When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
0
Attacker Value
Unknown
CVE-2020-10760
Disclosure Date: July 06, 2020 (last updated February 21, 2025)
A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samba LDAP user could use this flaw to crash samba.
0
Attacker Value
Unknown
CVE-2020-14303
Disclosure Date: July 06, 2020 (last updated February 21, 2025)
A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash.
0
Attacker Value
Unknown
CVE-2017-18922
Disclosure Date: June 30, 2020 (last updated February 21, 2025)
It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.
0