CVE-2021-2043
- EPSS 0.8%
- Veröffentlicht 20.01.2021 15:15:48
- Zuletzt bearbeitet 21.11.2024 06:02:15
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network acces...
CVE-2021-23926
- EPSS 0.44%
- Veröffentlicht 14.01.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:52:03
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.
CVE-2020-28052
- EPSS 4.1%
- Veröffentlicht 18.12.2020 01:15:12
- Zuletzt bearbeitet 12.05.2025 17:37:16
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previous...
CVE-2020-8286
- EPSS 0.29%
- Veröffentlicht 14.12.2020 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:38:39
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
CVE-2020-8284
- EPSS 0.1%
- Veröffentlicht 14.12.2020 20:15:13
- Zuletzt bearbeitet 16.04.2026 15:16:42
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed,...
CVE-2020-8285
- EPSS 0.74%
- Veröffentlicht 14.12.2020 20:15:13
- Zuletzt bearbeitet 16.04.2026 15:16:43
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
CVE-2020-8908
- EPSS 0.07%
- Veröffentlicht 10.12.2020 23:15:13
- Zuletzt bearbeitet 23.02.2026 21:17:30
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By defau...
CVE-2020-1971
- EPSS 0.35%
- Veröffentlicht 08.12.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:45
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they...
CVE-2020-13956
- EPSS 0.51%
- Veröffentlicht 02.12.2020 17:15:14
- Zuletzt bearbeitet 01.12.2025 16:15:48
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
CVE-2020-27193
- EPSS 1.01%
- Veröffentlicht 12.11.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:20:50
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.