CVE-2020-8203
- EPSS 2.44%
- Published 15.07.2020 17:15:11
- Last modified 21.11.2024 05:38:29
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
CVE-2020-11080
- EPSS 0.74%
- Published 03.06.2020 23:15:11
- Last modified 21.11.2024 04:56:44
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings e...
CVE-2020-10725
- EPSS 0.68%
- Published 20.05.2020 14:15:11
- Last modified 21.11.2024 04:55:56
A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that ...
CVE-2020-10726
- EPSS 0.15%
- Published 20.05.2020 14:15:11
- Last modified 21.11.2024 04:55:56
A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file descriptors and virtual memory), whi...
CVE-2020-10723
- EPSS 0.13%
- Published 19.05.2020 19:15:09
- Last modified 21.11.2024 04:55:55
A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out...
CVE-2020-10722
- EPSS 0.13%
- Published 19.05.2020 19:15:09
- Last modified 21.11.2024 04:55:55
A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.
CVE-2019-10219
- EPSS 1.67%
- Published 08.11.2019 15:15:11
- Last modified 07.07.2025 14:15:21
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
CVE-2019-9513
- EPSS 4.36%
- Published 13.08.2019 21:15:12
- Last modified 14.01.2025 19:29:55
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the...
CVE-2019-9511
- EPSS 13.95%
- Published 13.08.2019 21:15:12
- Last modified 14.01.2025 19:29:55
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. T...
CVE-2018-16865
- EPSS 2.07%
- Published 11.01.2019 21:29:00
- Last modified 21.11.2024 03:53:28
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remo...