CVE-2020-27193
- EPSS 1.01%
- Veröffentlicht 12.11.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:20:50
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
CVE-2020-24750
- EPSS 2%
- Veröffentlicht 17.09.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:16:00
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
CVE-2020-24616
- EPSS 2.68%
- Veröffentlicht 25.08.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:15:09
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
CVE-2020-13934
- EPSS 23.38%
- Veröffentlicht 14.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:10
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException co...
CVE-2020-13935
- EPSS 91.75%
- Veröffentlicht 14.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:10
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with inv...
CVE-2020-14195
- EPSS 9.06%
- Veröffentlicht 16.06.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:50
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
CVE-2020-14060
- EPSS 8.72%
- Veröffentlicht 14.06.2020 21:15:09
- Zuletzt bearbeitet 29.04.2026 20:09:04
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).
CVE-2020-14062
- EPSS 9.64%
- Veröffentlicht 14.06.2020 20:15:10
- Zuletzt bearbeitet 29.04.2026 20:10:00
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).
CVE-2020-14061
- EPSS 6.15%
- Veröffentlicht 14.06.2020 20:15:10
- Zuletzt bearbeitet 27.08.2025 21:15:35
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, o...
- EPSS 93.46%
- Veröffentlicht 20.05.2020 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:40:44
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the Persiste...