|
210111
|
9.9 |
CRITICAL
Network
|
anchore
|
engine
|
In Anchore Engine version 0.7.0, a specially crafted container image manifest, fetched from a registry, can be used to trigger a shell escape flaw in the anchore engine analyzer service during an ima…
|
NVD-CWE-Other
|
CVE-2020-11075
|
2024-11-21 13:56 |
2020-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210112
|
7.5 |
HIGH
Network
|
aegir_project
|
aegir
|
In AEgir greater than or equal to 21.7.0 and less than 21.10.1, aegir publish and aegir build may leak secrets from environment variables in the browser bundle published to npm. This has been fixed i…
|
CWE-200
Information Exposure
|
CVE-2020-11059
|
2024-11-21 13:56 |
2020-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210113
|
7.8 |
HIGH
Local
|
sympa fedoraproject debian canonical
|
sympa fedora debian_linux ubuntu_linux
|
Sympa before 6.2.56 allows privilege escalation.
|
CWE-269
Improper Privilege Management
|
CVE-2020-10936
|
2024-11-21 13:56 |
2020-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210114
|
6.1 |
MEDIUM
Network
|
centreon
|
centreon_host-monitoring_widget centreon_tactical-overview_widget centreon_service-monitoring_widget
|
Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page parameter to service-monitoring/src/index.php. This vulnerability is fixed in vers…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10946
|
2024-11-21 13:56 |
2020-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210115
|
4.3 |
MEDIUM
Adjacent
|
centreon
|
widget-host-monitoring centreon
|
Centreon before 19.10.7 exposes Session IDs in server responses.
|
CWE-200
Information Exposure
|
CVE-2020-10945
|
2024-11-21 13:56 |
2020-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210116
|
7.5 |
HIGH
Network
|
puma fedoraproject debian
|
puma fedora debian_linux
|
In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.
|
-
|
CVE-2020-11076
|
2024-11-21 13:56 |
2020-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210117
|
7.5 |
HIGH
Network
|
puma fedoraproject debian opensuse
|
puma fedora debian_linux leap
|
In Puma (RubyGem) before 4.3.5 and 3.12.6, a client could smuggle a request through a proxy, causing the proxy to send a response back to another unknown client. If the proxy uses persistent connecti…
|
-
|
CVE-2020-11077
|
2024-11-21 13:56 |
2020-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210118
|
6.8 |
MEDIUM
Network
|
httplib2_project fedoraproject debian
|
httplib2 fedora debian_linux
|
In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. T…
|
-
|
CVE-2020-11078
|
2024-11-21 13:56 |
2020-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210119
|
7.5 |
HIGH
Network
|
powerdns fedoraproject debian opensuse
|
recursor fedora debian_linux leap backports_sle
|
PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the DNS protocol has been found that allow malicious parties to use recu…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-10995
|
2024-11-21 13:56 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210120
|
5.3 |
MEDIUM
Network
|
dovecot
|
dovecot
|
In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart.
|
CWE-20
Improper Input Validation
|
CVE-2020-10967
|
2024-11-21 13:56 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|