|
208741
|
7.5 |
HIGH
Network
|
wireshark fedoraproject opensuse debian oracle
|
wireshark fedora leap debian_linux zfs_storage_appliance_firmware
|
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF che…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-25862
|
2024-11-21 14:18 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208742
|
7.2 |
HIGH
Network
|
craftercms
|
studio
|
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker template exposed objects. T…
|
CWE-913
Improper Control of Dynamically-Managed Code Resources
|
CVE-2020-25803
|
2024-11-21 14:18 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208743
|
3.2 |
LOW
Local
|
qemu redhat
|
qemu enterprise_linux openstack_platform
|
hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-25743
|
2024-11-21 14:18 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208744
|
3.2 |
LOW
Local
|
qemu
|
qemu
|
pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-25742
|
2024-11-21 14:18 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208745
|
7.2 |
HIGH
Network
|
craftercms
|
studio
|
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy scripting. This issue affects: …
|
CWE-913
Improper Control of Dynamically-Managed Code Resources
|
CVE-2020-25802
|
2024-11-21 14:18 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208746
|
7.5 |
HIGH
Network
|
redhat netapp
|
wildfly_openssl jboss_enterprise_application_platform single_sign-on jboss_fuse jboss_data_grid openshift_application_runtimes data_grid oncommand_workflow_automation oncomman…
|
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest …
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-25644
|
2024-11-21 14:18 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208747
|
7.2 |
HIGH
Network
|
linux redhat opensuse debian netapp starwindsoftware
|
linux_kernel enterprise_linux leap debian_linux h410c_firmware starwind_virtual_san
|
A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function wh…
|
-
|
CVE-2020-25643
|
2024-11-21 14:18 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208748
|
5.5 |
MEDIUM
Local
|
linux redhat opensuse debian canonical
|
linux_kernel enterprise_linux leap debian_linux ubuntu_linux
|
A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loo…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-25641
|
2024-11-21 14:18 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208749
|
6.7 |
MEDIUM
Local
|
redhat opensuse
|
libvirt leap
|
A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects…
|
-
|
CVE-2020-25637
|
2024-11-21 14:18 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208750
|
7.5 |
HIGH
Network
|
ruby-lang fedoraproject
|
ruby webrick fedora
|
An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigoro…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-25613
|
2024-11-21 14:18 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|