VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2020-15977MedNov 3, 2020
    risk 0.42cvss 6.5epss 0.01

    Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.

  • CVE-2020-15973MedNov 3, 2020
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in extensions in Google Chrome prior to 86.0.4240.75 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension.

  • CVE-2020-14775MedOct 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise…

  • CVE-2020-14769MedOct 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2020-14765MedOct 21, 2020
    risk 0.42cvss 6.5epss 0.03

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple…

  • CVE-2020-25613HigOct 6, 2020
    risk 0.42cvss 7.5epss 0.04

    An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issue to bypass a reverse proxy…

  • CVE-2020-8223MedOct 5, 2020
    risk 0.42cvss 6.5epss 0.01

    A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves.

  • CVE-2020-11979HigOct 1, 2020
    risk 0.42cvss 7.5epss 0.08

    As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively…

  • CVE-2020-25597MedSep 23, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Xen through 4.14.x. There is mishandling of the constraint that once-valid event channels may not turn invalid. Logic in the handling of event channel operations in Xen assumes that an event channel, once valid, will not become invalid over the life…

  • CVE-2020-6568MedSep 21, 2020
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2020-6567MedSep 21, 2020
    risk 0.42cvss 6.5epss 0.01

    Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2020-6566MedSep 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2020-6565MedSep 21, 2020
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2020-6564MedSep 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.

  • CVE-2020-6563MedSep 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.

  • CVE-2020-6562MedSep 21, 2020
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2020-6561MedSep 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2020-6560MedSep 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Insufficient policy enforcement in autofill in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2020-6547MedSep 21, 2020
    risk 0.42cvss 6.5epss 0.01

    Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page.

  • CVE-2020-6538MedSep 21, 2020
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

Page 126 of 268