VYPR

Leap

by OpenSUSE

Source repositories

CVEs (1,917)

  • CVE-2020-6558MedSep 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Insufficient policy enforcement in iOSWeb in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2019-20916HigSep 4, 2020
    risk 0.42cvss 7.5epss 0.03

    The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in…

  • CVE-2020-15810MedSep 2, 2020
    risk 0.42cvss 6.5epss 0.03

    An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggling attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local…

  • CVE-2020-25032HigAug 31, 2020
    risk 0.42cvss 7.5epss 0.04

    An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.

  • CVE-2020-17498MedAug 13, 2020
    risk 0.42cvss 6.5epss 0.03

    In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression.

  • CVE-2020-15655MedAug 10, 2020
    risk 0.42cvss 6.5epss 0.02

    A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-origin information. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

  • CVE-2020-16845HigAug 6, 2020
    risk 0.42cvss 7.5epss 0.05

    Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.

  • CVE-2020-14308MedJul 29, 2020
    risk 0.42cvss 6.4epss 0.00

    In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested allocation size. This leads the function to return invalid memory allocations which can be further used to cause possible integrity, confidentiality and…

  • CVE-2020-15706MedJul 29, 2020
    risk 0.42cvss 6.4epss 0.01

    GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This…

  • CVE-2020-15705MedJul 29, 2020
    risk 0.42cvss 6.4epss 0.01

    GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without…

  • CVE-2020-6526MedJul 22, 2020
    risk 0.42cvss 6.5epss 0.02

    Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2020-6521MedJul 22, 2020
    risk 0.42cvss 6.5epss 0.02

    Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2020-6511MedJul 22, 2020
    risk 0.42cvss 6.5epss 0.02

    Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2020-0305MedJul 17, 2020
    risk 0.42cvss 6.4epss 0.00

    In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID:…

  • CVE-2020-15803MedJul 17, 2020
    risk 0.42cvss 6.1epss 0.32

    Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.

  • CVE-2020-14711MedJul 15, 2020
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the…

  • CVE-2019-20907HigJul 13, 2020
    risk 0.42cvss 7.5epss 0.06

    In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.

  • CVE-2020-10756MedJul 9, 2020
    risk 0.42cvss 6.5epss 0.01

    An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents…

  • CVE-2020-12418MedJul 9, 2020
    risk 0.42cvss 6.5epss 0.03

    Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.

  • CVE-2020-12415MedJul 9, 2020
    risk 0.42cvss 6.5epss 0.01

    When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vulnerability affects Firefox <…

Page 45 of 96