CVE-2020-11728
- EPSS 0.45%
- Veröffentlicht 15.04.2020 16:15:16
- Zuletzt bearbeitet 21.11.2024 04:58:29
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a sess...
CVE-2020-11729
- EPSS 0.47%
- Veröffentlicht 15.04.2020 16:15:16
- Zuletzt bearbeitet 21.11.2024 04:58:29
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be successful.
CVE-2020-2933
- EPSS 0.13%
- Veröffentlicht 15.04.2020 14:15:36
- Zuletzt bearbeitet 21.11.2024 05:26:40
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 5.1.48 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple pro...
CVE-2020-2934
- EPSS 0.13%
- Veröffentlicht 15.04.2020 14:15:36
- Zuletzt bearbeitet 21.11.2024 05:26:40
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.19 and prior and 5.1.48 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network ac...
CVE-2020-2875
- EPSS 0.89%
- Veröffentlicht 15.04.2020 14:15:32
- Zuletzt bearbeitet 21.11.2024 05:26:30
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.14 and prior and 5.1.48 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network ac...
CVE-2020-2814
- EPSS 0.11%
- Veröffentlicht 15.04.2020 14:15:29
- Zuletzt bearbeitet 21.11.2024 05:26:20
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.6.47 and prior, 5.7.28 and prior and 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with net...
CVE-2020-2816
- EPSS 0.92%
- Veröffentlicht 15.04.2020 14:15:29
- Zuletzt bearbeitet 21.11.2024 05:26:21
Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Ja...
CVE-2020-2830
- EPSS 0.22%
- Veröffentlicht 15.04.2020 14:15:29
- Zuletzt bearbeitet 21.11.2024 05:26:23
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthe...
CVE-2020-2800
- EPSS 0.58%
- Veröffentlicht 15.04.2020 14:15:28
- Zuletzt bearbeitet 21.11.2024 05:26:18
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability ...
CVE-2020-2803
- EPSS 0.99%
- Veröffentlicht 15.04.2020 14:15:28
- Zuletzt bearbeitet 21.11.2024 05:26:18
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthe...