CVE-2020-0565
published 2020-03-12CVE-2020-0565: Uncontrolled search path in Intel(R) Graphics Drivers before version 26.20.100.7158 may allow an authenticated user to potentially enable escalation of…
PriorityP434high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.35%
27.0th percentile
Uncontrolled search path in Intel(R) Graphics Drivers before version 26.20.100.7158 may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | graphics_driver | < 26.20.100.7158 | 26.20.100.7158 |
| intel | intel_graphics_drivers | — | — |
| intel | intel_graphics_drivers | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-6793 Mozilla: Out-of-bounds read when processing certain email messages
bugzilla·2020-02-11·CVSS 6.5
CVE-2020-6793 [MEDIUM] CVE-2020-6793 Mozilla: Out-of-bounds read when processing certain email messages
CVE-2020-6793 Mozilla: Out-of-bounds read when processing certain email messages
When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2020-07/#CVE-2020-6793
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Chiaki ISHIKAWA
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
Via RHSA-2020:0565 https://access.redhat.com/errata/RHSA-2020:0565
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6793
---
This issue has been addressed in the following pro
Bugzilla
CVE-2020-6795 Mozilla: Crash processing S/MIME messages with multiple signatures
bugzilla·2020-02-11·CVSS 6.5
CVE-2020-6795 [MEDIUM] CVE-2020-6795 Mozilla: Crash processing S/MIME messages with multiple signatures
CVE-2020-6795 Mozilla: Crash processing S/MIME messages with multiple signatures
When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null pointer dereference, leading to an unexploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2020-07/#CVE-2020-6795
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Stephan Lauffer
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
Via RHSA-2020:0565 https://access.redhat.com/errata/RHSA-2020:0565
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6795
---
Bugzilla
CVE-2020-6792 Mozilla: Message ID calculation was based on uninitialized data
bugzilla·2020-02-11·CVSS 4.3
CVE-2020-6792 [MEDIUM] CVE-2020-6792 Mozilla: Message ID calculation was based on uninitialized data
CVE-2020-6792 Mozilla: Message ID calculation was based on uninitialized data
When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2020-07/#CVE-2020-6792
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Chiaki ISHIKAWA
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
Via RHSA-2020:0565 https://access.redhat.com/errata/RHSA-2020:0565
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6792
---
This issue has been addressed in the following products:
2020-03-12
Published