CVE-2020-36181
- EPSS 7.39%
- Veröffentlicht 06.01.2021 23:15:12
- Zuletzt bearbeitet 21.11.2024 05:28:55
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.
CVE-2020-35728
- EPSS 39.67%
- Veröffentlicht 27.12.2020 05:15:11
- Zuletzt bearbeitet 27.08.2025 21:15:36
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.js...
CVE-2020-28052
- EPSS 3.78%
- Veröffentlicht 18.12.2020 01:15:12
- Zuletzt bearbeitet 12.05.2025 17:37:16
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previous...
CVE-2020-15824
- EPSS 0.03%
- Veröffentlicht 08.08.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:06:15
In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is ...
CVE-2020-8174
- EPSS 1.49%
- Veröffentlicht 24.07.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:26
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
CVE-2020-8203
- EPSS 2.44%
- Veröffentlicht 15.07.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:38:29
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
CVE-2020-8172
- EPSS 1.18%
- Veröffentlicht 08.06.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:38:26
TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
CVE-2020-11080
- EPSS 0.74%
- Veröffentlicht 03.06.2020 23:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:44
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings e...
CVE-2020-10531
- EPSS 0.79%
- Veröffentlicht 12.03.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:55:31
An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.
CVE-2019-10744
- EPSS 3.41%
- Veröffentlicht 26.07.2019 00:15:11
- Zuletzt bearbeitet 21.11.2024 04:19:50
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.