Security Vulnerabilities
- CVEs Published In November 2020
Azure Sphere Elevation of Privilege Vulnerability
Azure Sphere Unsigned Code Execution Vulnerability
Azure Sphere Tampering Vulnerability
Azure Sphere Unsigned Code Execution Vulnerability
Azure Sphere Information Disclosure Vulnerability
Azure Sphere Denial of Service Vulnerability
Azure Sphere Unsigned Code Execution Vulnerability
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, improperly dropped the ruid, allowing untrusted users to send signals to AccountService, thus stopping it from handling D-Bus messages in a timely fashion.
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an infinite loop if /dev/zero is symlinked to this location.
An XSS issue exists in the question-pool file-upload preview feature in ILIAS 6.4.