Number of Reported Breaches Decrease In First Half of 2020

Number of Reported Breaches Decrease In First Half of 2020
Enterprise VulnerabilitiesFrom DHS/US-CERT's National Vulnerability Database CVE-2020-15852PUBLISHED: 2020-07-20

An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization between the I/O bitmaps ...

CVE-2020-15111PUBLISHED: 2020-07-20

In Fiber before version 1.12.6, the filename that is given in c.Attachment() (https://docs.gofiber.io/ctx#attachment) is not escaped, and therefore vulnerable for a CRLF injection attack. I.e. an attacker could upload a custom filename and then give the link to the victim. With this filename, the at...

CVE-2020-15118PUBLISHED: 2020-07-20

In Wagtail before versions 2.7.4 and 2.9.3, when a form page type is made available to Wagtail editors through the `wagtail.contrib.forms` app, and the page template is built using Django's standard form rendering helpers such as form.as_p, any HTML tags used within a form field's help text will be ...

CVE-2020-15121PUBLISHED: 2020-07-20

In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned in the ..

Support the originator by clicking the read the rest link below.