VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2020-14559MedJul 15, 2020
    risk 0.28cvss 4.3epss 0.02

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 5.6.48 and prior, 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network…

  • CVE-2020-14553MedJul 15, 2020
    risk 0.28cvss 4.3epss 0.02

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple…

  • CVE-2020-4046MedJun 12, 2020
    risk 0.28cvss 5.4epss 0.02

    In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a higher privileged user, this could lead to script execution in…

  • CVE-2020-10754MedJun 8, 2020
    risk 0.28cvss 4.3epss 0.01

    It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made…

  • CVE-2020-6490MedMay 21, 2020
    risk 0.28cvss 4.3epss 0.01

    Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page.

  • CVE-2020-6489MedMay 21, 2020
    risk 0.28cvss 4.3epss 0.02

    Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced the user to take certain actions in developer tools to obtain potentially sensitive information from disk via a crafted HTML page.

  • CVE-2020-6488MedMay 21, 2020
    risk 0.28cvss 4.3epss 0.02

    Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2020-13230MedMay 20, 2020
    risk 0.28cvss 4.3epss 0.01

    In Cacti before 1.2.11, disabling a user account does not immediately invalidate any permissions granted to that account (e.g., permission to view logs).

  • CVE-2020-6442MedApr 13, 2020
    risk 0.28cvss 4.3epss 0.02

    Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2020-6441MedApr 13, 2020
    risk 0.28cvss 4.3epss 0.02

    Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page.

  • CVE-2020-6440MedApr 13, 2020
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.

  • CVE-2020-6438MedApr 13, 2020
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.

  • CVE-2020-6437MedApr 13, 2020
    risk 0.28cvss 4.3epss 0.02

    Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted application.

  • CVE-2020-6435MedApr 13, 2020
    risk 0.28cvss 4.3epss 0.02

    Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.

  • CVE-2020-6433MedApr 13, 2020
    risk 0.28cvss 4.3epss 0.02

    Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2020-6432MedApr 13, 2020
    risk 0.28cvss 4.3epss 0.02

    Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2020-6431MedApr 13, 2020
    risk 0.28cvss 4.3epss 0.02

    Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted HTML page.

  • CVE-2020-8552MedMar 27, 2020
    risk 0.28cvss 5.3epss 0.02

    The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.

  • CVE-2020-7042MedFeb 27, 2020
    risk 0.28cvss 5.3epss 0.02

    An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate…

  • CVE-2020-7041MedFeb 27, 2020
    risk 0.28cvss 5.3epss 0.02

    An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a successful return value.

Page 197 of 268