CVE-2020-1967
- EPSS 53.34%
- Veröffentlicht 21.04.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:45
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occur...
CVE-2020-2952
- EPSS 1.21%
- Veröffentlicht 15.04.2020 14:15:37
- Zuletzt bearbeitet 21.11.2024 05:26:43
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP...
CVE-2020-2545
- EPSS 1.49%
- Veröffentlicht 15.01.2020 17:15:16
- Zuletzt bearbeitet 21.11.2024 05:25:29
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OSSL Module). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker wit...
CVE-2020-2530
- EPSS 1.09%
- Veröffentlicht 15.01.2020 17:15:15
- Zuletzt bearbeitet 21.11.2024 05:25:27
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker wi...
CVE-2019-10219
- EPSS 2.17%
- Veröffentlicht 08.11.2019 15:15:11
- Zuletzt bearbeitet 25.08.2026 16:28:27
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
CVE-2019-10082
- EPSS 16.55%
- Veröffentlicht 26.09.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:18:21
In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown.
CVE-2019-10097
- EPSS 52.87%
- Veröffentlicht 26.09.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:18:23
In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL pointer deference. This vulner...
CVE-2019-5482
- EPSS 17.94%
- Veröffentlicht 16.09.2019 19:15:10
- Zuletzt bearbeitet 15.04.2026 21:17:01
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
CVE-2019-2751
- EPSS 1.42%
- Veröffentlicht 23.07.2019 23:15:39
- Zuletzt bearbeitet 21.11.2024 04:41:28
Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: OHS Config MBeans). Supported versions that are affected are 12.1.3.0.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows unauthenticated attacker wi...
CVE-2019-5443
- EPSS 0.69%
- Veröffentlicht 02.07.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 04:44:56
A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privile...