|
197871
|
9.8 |
CRITICAL
Network
|
rust-lang
|
rust
|
In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain condition. This bug could result in a use-after-free or doub…
|
CWE-415 CWE-416
Double Free Use After Free
|
CVE-2020-36318
|
2024-11-21 14:29 |
2021-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197872
|
7.5 |
HIGH
Network
|
rust-lang
|
rust
|
In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem. It allows creation of a non-UTF-8 Rust string when the provided closure panics. This bug could res…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-36317
|
2024-11-21 14:29 |
2021-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197873
|
5.3 |
MEDIUM
Network
|
atlassian
|
data_center jira jira_server jira_data_center
|
The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote a…
|
CWE-862
Missing Authorization
|
CVE-2020-36287
|
2024-11-21 14:29 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197874
|
5.5 |
MEDIUM
Local
|
relic_project
|
relic
|
In RELIC before 2021-04-03, there is a buffer overflow in PKCS#1 v1.5 signature verification because garbage bytes can be present.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-36316
|
2024-11-21 14:29 |
2021-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197875
|
5.3 |
MEDIUM
Network
|
relic_project
|
relic
|
In RELIC before 2020-08-01, RSA PKCS#1 v1.5 signature forgery can occur because certain checks of the padding (and of the first two bytes) are inadequate. NOTE: this requires that a low public expone…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-36315
|
2024-11-21 14:29 |
2021-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197876
|
3.9 |
LOW
Local
|
gnome fedoraproject
|
file-roller fedora
|
fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's paren…
|
CWE-59
Link Following
|
CVE-2020-36314
|
2024-11-21 14:29 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197877
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
An issue was discovered in the Linux kernel before 5.7. The KVM subsystem allows out-of-range access to memslots after a deletion, aka CID-0774a964ef56. This affects arch/s390/kvm/kvm-s390.c, include…
|
CWE-416
Use After Free
|
CVE-2020-36313
|
2024-11-21 14:29 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197878
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
An issue was discovered in the Linux kernel before 5.8.10. virt/kvm/kvm_main.c has a kvm_io_bus_unregister_dev memory leak upon a kmalloc failure, aka CID-f65886606c2d.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-36312
|
2024-11-21 14:29 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197879
|
5.5 |
MEDIUM
Local
|
linux debian
|
linux_kernel debian_linux
|
An issue was discovered in the Linux kernel before 5.9. arch/x86/kvm/svm/sev.c allows attackers to cause a denial of service (soft lockup) by triggering destruction of a large SEV VM (which requires …
|
NVD-CWE-noinfo
|
CVE-2020-36311
|
2024-11-21 14:29 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197880
|
5.5 |
MEDIUM
Local
|
linux debian
|
linux_kernel debian_linux
|
An issue was discovered in the Linux kernel before 5.8. arch/x86/kvm/svm/svm.c allows a set_memory_region_test infinite loop for certain nested page faults, aka CID-e72436bc3a52.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-36310
|
2024-11-21 14:29 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|