CVE-2020-0003
published 2020-01-08CVE-2020-0003: In onCreate of InstallStart.java, there is a possible package validation bypass due to a time-of-check time-of-use vulnerability. This could lead to local…
PriorityP427medium6.7CVSS 3.1
AVLACHPRLUIRSUCHIHAH
EPSS
0.14%
3.8th percentile
In onCreate of InstallStart.java, there is a possible package validation bypass due to a time-of-check time-of-use vulnerability. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.0 Android ID: A-140195904
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-362v-m99f-grr8: In onCreate of InstallStart
ghsa_unreviewed·2022-05-24
CVE-2020-0003 [LOW] CWE-367 GHSA-362v-m99f-grr8: In onCreate of InstallStart
In onCreate of InstallStart.java, there is a possible package validation bypass due to a time-of-check time-of-use vulnerability. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.0 Android ID: A-140195904
VMware
vRealize Operations for Horizon Adapter updates address multiple security vulnerabilities (CVE-2020-3943, CVE-2020-3944, CVE-2020-3945)
vendor_vmware·2020-02-18·CVSS 9.8
CVE-2020-3943 [CRITICAL] vRealize Operations for Horizon Adapter updates address multiple security vulnerabilities (CVE-2020-3943, CVE-2020-3944, CVE-2020-3945)
VMSA-2020-0003: vRealize Operations for Horizon Adapter updates address multiple security vulnerabilities (CVE-2020-3943, CVE-2020-3944, CVE-2020-3945)
vRealize Operations for Horizon Adapter uses a JMX RMI service which is not securely configured. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.0.
CVEs: CVE-2020-3943, CVE-2020-3944, CVE-2020-3945
Affected products: VMware Aria
Android
CVE-2020-0003: Android Security Bulletin 2020-01-01
CVE: CVE-2020-0003
Severity: HIGH
Type: EoP
Affected AOSP versions: 8
vendor_android·2020-01-01·CVSS 6.7
CVE-2020-0003 [MEDIUM] CVE-2020-0003: Android Security Bulletin 2020-01-01
CVE: CVE-2020-0003
Severity: HIGH
Type: EoP
Affected AOSP versions: 8
Android Security Bulletin 2020-01-01
CVE: CVE-2020-0003
Severity: HIGH
Type: EoP
Affected AOSP versions: 8.0
References: A-140195904
Suricata
ET WEB_CLIENT Likely MS12-004 midiOutPlayNextPolyEvent Heap Overflow Midi Filename Requested baby.mid
suricata·2012-02-07
CVE-2012-0003 ET WEB_CLIENT Likely MS12-004 midiOutPlayNextPolyEvent Heap Overflow Midi Filename Requested baby.mid
ET WEB_CLIENT Likely MS12-004 midiOutPlayNextPolyEvent Heap Overflow Midi Filename Requested baby.mid
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET WEB_CLIENT Likely MS12-004 midiOutPlayNextPolyEvent Heap Overflow Midi Filename Requested baby.mid"; flow:established,to_server; http.uri; content:"/baby.mid"; reference:cve,2012-0003; classtype:trojan-activity; sid:2014207; rev:4; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2012_02_07, cve CVE_2012_0003, deployment Perimeter, confidence Low, signature_severity Major, tag Web_Client_Attacks, updated_at 2020_05_08;)
No public exploits indexed.
arXiv
Vulnerability Forecasting: In theory and practice
arxiv_fulltext·2020-12-07
Vulnerability Forecasting: In theory and practice
Vulnerability Forecasting: In theory and practice.
\'Eireann Leverett
Both authors contributed equally to this research.
[email protected]
0000-0001-6586-7359
Matilda Rhode
[1]
[email protected]
Adam Wedgbury
[email protected]
Airbus
Quadrant House, Celtic Springs Business Park, Coedkernew, Duffryn
Newport
U.K.
NP10 8FZ
## Abstract
Why wait for zero-days when you could predict them in advance? It is possible to predict the volume of CVEs released in the NVD as much as a year in advance. This can be done within 3 percent of the actual value, and different predictive algorithms perform well at different lookahead values. It is also possible to estimate the proportions of that total volumn belonging to specific vendors, software, CVSS scores, or vulnerability types
Bugzilla
CVE-2019-8619 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8619 [HIGH] CVE-2019-8619 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8619 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8619
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8622 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8622 [HIGH] CVE-2019-8622 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8622 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8622
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8610 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8610 [HIGH] CVE-2019-8610 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8610 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8610
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8594 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8594 [HIGH] CVE-2019-8594 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8594 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8594
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8597 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 6.5
CVE-2019-8597 [MEDIUM] CVE-2019-8597 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8597 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8597
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8587 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8587 [HIGH] CVE-2019-8587 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8587 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8587
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8611 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8611 [HIGH] CVE-2019-8611 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8611 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8611
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-6237 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-6237 [HIGH] CVE-2019-6237 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-6237 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-6237
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8607 webkitgtk: Out-of-bounds read leading to memory disclosure
bugzilla·2020-09-08·CVSS 6.5
CVE-2019-8607 [MEDIUM] CVE-2019-8607 webkitgtk: Out-of-bounds read leading to memory disclosure
CVE-2019-8607 webkitgtk: Out-of-bounds read leading to memory disclosure
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8607
Processing maliciously crafted web content may result in the disclosure of process memory. An out-of-bounds read was addressed with improved input validation.
Versions affected: WebKitGTK and WPE WebKit before 2.24.2.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-8607
Bugzilla
CVE-2019-8601 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8601 [HIGH] CVE-2019-8601 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8601 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8601
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8596 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8596 [HIGH] CVE-2019-8596 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8596 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8596
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8609 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8609 [HIGH] CVE-2019-8609 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8609 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8609
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8586 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8586 [HIGH] CVE-2019-8586 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8586 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8586
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8623 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8623 [HIGH] CVE-2019-8623 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8623 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8623
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8608 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 6.3
CVE-2019-8608 [MEDIUM] CVE-2019-8608 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8608 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8608
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8595 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8595 [HIGH] CVE-2019-8595 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8595 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8595
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.2.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8584 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8584 [HIGH] CVE-2019-8584 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8584 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8584
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8615 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 6.5
CVE-2019-8615 [MEDIUM] CVE-2019-8615 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8615 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8615
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.2.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8583 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8583 [HIGH] CVE-2019-8583 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8583 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8583
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8571 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8571 [HIGH] CVE-2019-8571 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8571 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8571
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2020-7014 elasticsearch: Incomplete fix for CVE-2020-7009 could result in generating API key with elevated privileges
bugzilla·2020-06-19·CVSS 8.8
CVE-2020-7014 [HIGH] CVE-2020-7014 elasticsearch: Incomplete fix for CVE-2020-7009 could result in generating API key with elevated privileges
CVE-2020-7014 elasticsearch: Incomplete fix for CVE-2020-7009 could result in generating API key with elevated privileges
The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.
References:
https://security.netapp.com/advisory/ntap-20200619-0003/
https://www.elastic.co/community/security/
Discussion:
Statement:
OpenShift Container Platform 4.x and 3.11 use Elasticsearch 5.6 which does not have the API Keys feature.
---
This bug is n
2020-01-08
Published