- EPSS 0.03%
- Veröffentlicht 23.10.2020 13:15:16
- Zuletzt bearbeitet 21.11.2024 05:20:52
In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can obser...
CVE-2020-25648
- EPSS 0.12%
- Veröffentlicht 20.10.2020 22:15:43
- Zuletzt bearbeitet 21.11.2024 05:18:20
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this ...
CVE-2020-8203
- EPSS 2.44%
- Veröffentlicht 15.07.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:38:29
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
CVE-2020-11023
- EPSS 21.32%
- Veröffentlicht 29.04.2020 21:15:11
- Zuletzt bearbeitet 24.01.2025 02:00:02
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may ex...
CVE-2020-2733
- EPSS 90.05%
- Veröffentlicht 15.04.2020 14:15:22
- Zuletzt bearbeitet 21.11.2024 05:26:07
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network acc...
CVE-2020-11619
- EPSS 1.73%
- Veröffentlicht 07.04.2020 23:15:12
- Zuletzt bearbeitet 21.11.2024 04:58:15
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).
CVE-2020-11620
- EPSS 2.8%
- Veröffentlicht 07.04.2020 23:15:12
- Zuletzt bearbeitet 21.11.2024 04:58:15
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
CVE-2020-11111
- EPSS 2.2%
- Veröffentlicht 31.03.2020 05:15:13
- Zuletzt bearbeitet 21.11.2024 04:56:48
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
CVE-2020-11112
- EPSS 11.42%
- Veröffentlicht 31.03.2020 05:15:13
- Zuletzt bearbeitet 21.11.2024 04:56:49
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
CVE-2020-11113
- EPSS 60.71%
- Veröffentlicht 31.03.2020 05:15:13
- Zuletzt bearbeitet 21.11.2024 04:56:49
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).