
Look up vulnerabilities by software, product or CVE number.
| CVE | Published | CVSS | ShadowTrackr CVSS | Summary |
|---|---|---|---|---|
CVE: CVE-2020-3631 | Published 2021-12-20 | CVSS: - | ShadowTrackr CVSS: 0.0 | Summary: |
CVE: CVE-2020-36319 | Published 2021-04-23 | CVSS: 3.1 | ShadowTrackr CVSS: 1.3 | Summary: Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. @RestController |
CVE: CVE-2020-36317 | Published 2021-04-11 | CVSS: 7.5 | ShadowTrackr CVSS: 6.9 | Summary: In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem. It allows creation of a non-UTF-8 Rust string when the provided closure panics. This bug could result in a memory safety violation when other string APIs assume that UTF-8 encoding is used on the same string. |
CVE: CVE-2020-36318 | Published 2021-04-11 | CVSS: 9.8 | ShadowTrackr CVSS: 8.2 | Summary: In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain condition. This bug could result in a use-after-free or double free. |
CVE: CVE-2020-36315 | Published 2021-04-07 | CVSS: 5.3 | ShadowTrackr CVSS: 1.7 | Summary: In RELIC before 2020-08-01, RSA PKCS#1 v1.5 signature forgery can occur because certain checks of the padding (and of the first two bytes) are inadequate. NOTE: this requires that a low public exponent (such as 3) is being used. The product, by default, does not generate RSA keys with such a low number. |
CVE: CVE-2020-36316 | Published 2021-04-07 | CVSS: 5.5 | ShadowTrackr CVSS: 1.7 | Summary: In RELIC before 2021-04-03, there is a buffer overflow in PKCS#1 v1.5 signature verification because garbage bytes can be present. |
CVE: CVE-2020-36314 | Published 2021-04-07 | CVSS: 3.9 | ShadowTrackr CVSS: 0.3 | Summary: fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736. |
CVE: CVE-2020-36310 | Published 2021-04-06 | CVSS: 5.5 | ShadowTrackr CVSS: 1.9 | Summary: An issue was discovered in the Linux kernel before 5.8. arch/x86/kvm/svm/svm.c allows a set_memory_region_test infinite loop for certain nested page faults, aka CID-e72436bc3a52. |
CVE: CVE-2020-36311 | Published 2021-04-06 | CVSS: 5.5 | ShadowTrackr CVSS: 1.9 | Summary: An issue was discovered in the Linux kernel before 5.9. arch/x86/kvm/svm/sev.c allows attackers to cause a denial of service (soft lockup) by triggering destruction of a large SEV VM (which requires unregistering many encrypted regions), aka CID-7be74942f184. |
CVE: CVE-2020-36312 | Published 2021-04-06 | CVSS: 5.5 | ShadowTrackr CVSS: 1.9 | Summary: An issue was discovered in the Linux kernel before 5.8.10. virt/kvm/kvm_main.c has a kvm_io_bus_unregister_dev memory leak upon a kmalloc failure, aka CID-f65886606c2d. |
CVE: CVE-2020-36313 | Published 2021-04-06 | CVSS: 7.8 | ShadowTrackr CVSS: 6.4 | Summary: An issue was discovered in the Linux kernel before 5.7. The KVM subsystem allows out-of-range access to memslots after a deletion, aka CID-0774a964ef56. This affects arch/s390/kvm/kvm-s390.c, include/linux/kvm_host.h, and virt/kvm/kvm_main.c. |