CVE-2020-7699
- EPSS 4.09%
- Veröffentlicht 30.07.2020 09:15:11
- Zuletzt bearbeitet 21.11.2024 05:37:38
This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.
CVE-2020-15801
- EPSS 0.73%
- Veröffentlicht 17.07.2020 03:15:11
- Zuletzt bearbeitet 21.11.2024 05:06:12
In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The <executable-name>._pth file (e.g., the python._pth file) is not affected.
CVE-2020-14966
- EPSS 0.28%
- Veröffentlicht 22.06.2020 12:15:10
- Zuletzt bearbeitet 21.11.2024 05:04:31
An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signatures by not checking overflows in the length of a sequence and '0' characters appended or prepended to an integer. The modified signa...
CVE-2020-14967
- EPSS 0.34%
- Veröffentlicht 22.06.2020 12:15:10
- Zuletzt bearbeitet 21.11.2024 05:04:32
An issue was discovered in the jsrsasign package before 8.0.18 for Node.js. Its RSA PKCS1 v1.5 decryption implementation does not detect ciphertext modification by prepending '\0' bytes to ciphertexts (it decrypts modified ciphertexts without error)....
CVE-2020-14968
- EPSS 0.55%
- Veröffentlicht 22.06.2020 12:15:10
- Zuletzt bearbeitet 21.11.2024 05:04:32
An issue was discovered in the jsrsasign package before 8.0.17 for Node.js. Its RSASSA-PSS (RSA-PSS) implementation does not detect signature manipulation/modification by prepending '\0' bytes to a signature (it accepts these modified signatures as v...
CVE-2020-11022
- EPSS 22.55%
- Veröffentlicht 29.04.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:36
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This prob...
CVE-2020-11023
- EPSS 21.32%
- Veröffentlicht 29.04.2020 21:15:11
- Zuletzt bearbeitet 24.01.2025 02:00:02
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may ex...