CVE-2020-24616
- EPSS 3.78%
- Veröffentlicht 25.08.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:15:09
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
CVE-2020-8622
- EPSS 0.6%
- Veröffentlicht 21.08.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:39:08
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed re...
CVE-2020-11994
- EPSS 1.55%
- Veröffentlicht 08.07.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:04
Server-Side Template Injection and arbitrary file disclosure on Camel templating components
CVE-2020-14195
- EPSS 9.51%
- Veröffentlicht 16.06.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:50
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
CVE-2020-14060
- EPSS 8.72%
- Veröffentlicht 14.06.2020 21:15:09
- Zuletzt bearbeitet 21.11.2024 05:02:27
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).
CVE-2020-14062
- EPSS 7.71%
- Veröffentlicht 14.06.2020 20:15:10
- Zuletzt bearbeitet 21.11.2024 05:02:28
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).
CVE-2020-14061
- EPSS 6.15%
- Veröffentlicht 14.06.2020 20:15:10
- Zuletzt bearbeitet 27.08.2025 21:15:35
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, o...
CVE-2020-12723
- EPSS 0.18%
- Veröffentlicht 05.06.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 05:00:08
regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls.
CVE-2020-10878
- EPSS 0.11%
- Veröffentlicht 05.06.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:56:16
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection.
CVE-2020-10543
- EPSS 3.94%
- Veröffentlicht 05.06.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:55:32
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.