CVE-2020-8277
- EPSS 59.17%
- Veröffentlicht 19.11.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:38
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number...
CVE-2020-7774
- EPSS 0.68%
- Veröffentlicht 17.11.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:37:46
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
- EPSS 0.04%
- Veröffentlicht 21.10.2020 15:15:20
- Zuletzt bearbeitet 27.05.2025 16:40:04
Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 11.0.8 and 15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocol...
CVE-2020-14718
- EPSS 1.32%
- Veröffentlicht 15.07.2020 18:15:35
- Zuletzt bearbeitet 21.11.2024 05:03:58
Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: JVMCI). Supported versions that are affected are 19.3.2 and 20.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via ...
CVE-2020-8172
- EPSS 1.18%
- Veröffentlicht 08.06.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:38:26
TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
CVE-2020-11080
- EPSS 0.74%
- Veröffentlicht 03.06.2020 23:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:44
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings e...
CVE-2020-2900
- EPSS 0.3%
- Veröffentlicht 15.04.2020 14:15:34
- Zuletzt bearbeitet 21.11.2024 05:26:35
Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: Tools). Supported versions that are affected are 19.3.1 and 20.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via...
CVE-2020-2802
- EPSS 0.39%
- Veröffentlicht 15.04.2020 14:15:28
- Zuletzt bearbeitet 21.11.2024 05:26:18
Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: GraalVM Compiler). Supported versions that are affected are 19.3.1 and 20.0.0. Easily exploitable vulnerability allows low privileged attacker with network a...
CVE-2020-2799
- EPSS 0.45%
- Veröffentlicht 15.04.2020 14:15:27
- Zuletzt bearbeitet 21.11.2024 05:26:18
Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: GraalVM Compiler). Supported versions that are affected are 19.3.1 and 20.0.0. Difficult to exploit vulnerability allows low privileged attacker with network...
CVE-2019-17560
- EPSS 1.92%
- Veröffentlicht 30.03.2020 19:15:15
- Zuletzt bearbeitet 21.11.2024 04:32:31
The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. “Apache N...