|
631
|
7.5
5.0
|
HIGH
Network
|
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-25648
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 14:18
2020-10-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
632
|
6.6
6.5
|
MEDIUM
Network
|
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affe…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-14355
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 14:03
2020-10-8
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
633
|
3.2
2.1
|
LOW
Local
|
hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-25743
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 14:18
2020-10-7
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
634
|
7.2
7.5
|
HIGH
Network
|
A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function wh…
|
-
|
CVE-2020-25643
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 14:18
2020-10-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
635
|
5.5
4.9
|
MEDIUM
Local
|
A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loo…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-25641
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 14:18
2020-10-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
636
|
5.3
4.0
|
MEDIUM
Network
|
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are cr…
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2020-14370
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 14:03
2020-09-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
637
|
7.8
6.8
|
HIGH
Local
|
A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, that is effectively invoked on every device/image presenting itself as LUKS2 conta…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-14382
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 14:03
2020-09-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
638
|
7.8
4.6
|
HIGH
Local
|
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vul…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2020-14362
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 14:03
2020-09-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
639
|
7.8
4.6
|
HIGH
Local
|
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vul…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2020-14361
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 14:03
2020-09-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
640
|
7.8
4.6
|
HIGH
Local
|
A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat …
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2020-14346
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 14:03
2020-09-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|