ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

11 results for “CVE-2020-3631”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-3631
Published
2021-12-20
CVSS:
-
ShadowTrackr CVSS:
0.0
Summary:
CVE:
CVE-2020-36319
Published
2021-04-23
CVSS:
3.1
ShadowTrackr CVSS:
1.3
Summary:
Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. @RestController
CVE:
CVE-2020-36317
Published
2021-04-11
CVSS:
7.5
ShadowTrackr CVSS:
6.9
Summary:
In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem. It allows creation of a non-UTF-8 Rust string when the provided closure panics. This bug could result in a memory safety violation when other string APIs assume that UTF-8 encoding is used on the same string.
CVE:
CVE-2020-36318
Published
2021-04-11
CVSS:
9.8
ShadowTrackr CVSS:
8.2
Summary:
In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain condition. This bug could result in a use-after-free or double free.
CVE:
CVE-2020-36315
Published
2021-04-07
CVSS:
5.3
ShadowTrackr CVSS:
1.7
Summary:
In RELIC before 2020-08-01, RSA PKCS#1 v1.5 signature forgery can occur because certain checks of the padding (and of the first two bytes) are inadequate. NOTE: this requires that a low public exponent (such as 3) is being used. The product, by default, does not generate RSA keys with such a low number.
CVE:
CVE-2020-36316
Published
2021-04-07
CVSS:
5.5
ShadowTrackr CVSS:
1.7
Summary:
In RELIC before 2021-04-03, there is a buffer overflow in PKCS#1 v1.5 signature verification because garbage bytes can be present.
CVE:
CVE-2020-36314
Published
2021-04-07
CVSS:
3.9
ShadowTrackr CVSS:
0.3
Summary:
fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.
CVE:
CVE-2020-36310
Published
2021-04-06
CVSS:
5.5
ShadowTrackr CVSS:
1.9
Summary:
An issue was discovered in the Linux kernel before 5.8. arch/x86/kvm/svm/svm.c allows a set_memory_region_test infinite loop for certain nested page faults, aka CID-e72436bc3a52.
CVE:
CVE-2020-36311
Published
2021-04-06
CVSS:
5.5
ShadowTrackr CVSS:
1.9
Summary:
An issue was discovered in the Linux kernel before 5.9. arch/x86/kvm/svm/sev.c allows attackers to cause a denial of service (soft lockup) by triggering destruction of a large SEV VM (which requires unregistering many encrypted regions), aka CID-7be74942f184.
CVE:
CVE-2020-36312
Published
2021-04-06
CVSS:
5.5
ShadowTrackr CVSS:
1.9
Summary:
An issue was discovered in the Linux kernel before 5.8.10. virt/kvm/kvm_main.c has a kvm_io_bus_unregister_dev memory leak upon a kmalloc failure, aka CID-f65886606c2d.
CVE:
CVE-2020-36313
Published
2021-04-06
CVSS:
7.8
ShadowTrackr CVSS:
6.4
Summary:
An issue was discovered in the Linux kernel before 5.7. The KVM subsystem allows out-of-range access to memslots after a deletion, aka CID-0774a964ef56. This affects arch/s390/kvm/kvm-s390.c, include/linux/kvm_host.h, and virt/kvm/kvm_main.c.