|
681
|
5.9
5.8
|
MEDIUM
Network
|
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious contain…
|
-
|
CVE-2020-1726
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 14:11
2020-02-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
682
|
6.0
6.0
|
MEDIUM
Network
|
An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-1711
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 14:11
2020-02-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
683
|
6.8
7.2
|
MEDIUM
Physics
|
Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 allows physically proximate attackers to execute arbitrary code, cause a denial of…
|
CWE-120
Classic Buffer Overflow
|
CVE-2009-4067
|
cpe:2.3:o:redhat:enterprise_linux:4.0:*
|
|
|
|
|
2024-11-21 10:08
2020-02-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
684
|
9.8
7.5
|
CRITICAL
Network
|
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contai…
|
CWE-444
HTTP Request Smuggling
|
CVE-2015-5741
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 11:33
2020-02-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
685
|
8.8
6.8
|
HIGH
Network
|
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "ty…
|
CWE-843
Type Confusion
|
CVE-2012-4512
|
cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 10:43
2020-02-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
686
|
9.8
7.5
|
CRITICAL
Network
|
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
|
NVD-CWE-Other
|
CVE-2019-15606
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 13:29
2020-02-8
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
687
|
9.8
7.5
|
CRITICAL
Network
|
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-15605
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 13:29
2020-02-8
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
688
|
7.5
5.0
|
HIGH
Network
|
Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate
|
CWE-295
Improper Certificate Validation
|
CVE-2019-15604
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 13:29
2020-02-8
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
689
|
3.5
2.7
|
LOW
Adjacent
|
The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of ser…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2015-6815
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 11:35
2020-02-1
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
690
|
7.5
5.0
|
HIGH
Network
|
GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
|
CWE-295
Improper Certificate Validation
|
CVE-2015-0294
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:5.0:*
|
|
|
|
|
2024-11-21 11:22
2020-01-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|