CVE-2021-21702
- EPSS 0.25%
- Published 15.02.2021 04:15:12
- Last modified 21.11.2024 05:48:51
In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer a...
CVE-2020-36189
- EPSS 3.37%
- Published 06.01.2021 23:15:13
- Last modified 21.11.2024 05:28:58
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.
CVE-2020-35490
- EPSS 5.58%
- Published 17.12.2020 19:15:14
- Last modified 21.11.2024 05:27:24
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.
CVE-2020-17521
- EPSS 0.36%
- Published 07.12.2020 20:15:12
- Last modified 21.11.2024 05:08:16
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operatin...
CVE-2020-14788
- EPSS 0.64%
- Published 21.10.2020 15:15:18
- Last modified 21.11.2024 05:04:09
Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: User Interface). Supported versions that are affected are 8.0.0.0-8.4.0.5. Easily exploitable vulnerability allows unauthenticated...
CVE-2020-14787
- EPSS 0.19%
- Published 21.10.2020 15:15:18
- Last modified 21.11.2024 05:04:09
Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: User Interface). Supported versions that are affected are 8.0.0.0-8.4.0.5. Easily exploitable vulnerability allows low privileged ...
CVE-2020-7069
- EPSS 8.35%
- Published 02.10.2020 15:15:12
- Last modified 21.11.2024 05:36:36
In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and inc...
CVE-2020-24750
- EPSS 2.11%
- Published 17.09.2020 19:15:13
- Last modified 21.11.2024 05:16:00
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
CVE-2020-11998
- EPSS 7.58%
- Published 10.09.2020 19:15:13
- Last modified 21.11.2024 04:59:05
A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack: https:...
CVE-2020-13920
- EPSS 0.15%
- Published 10.09.2020 19:15:13
- Last modified 21.11.2024 05:02:09
Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something ...