CVE-2020-10955
- EPSS 0.18%
- Published 27.03.2020 19:15:11
- Last modified 21.11.2024 04:56:26
GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.
CVE-2020-1770
- EPSS 0.36%
- Published 27.03.2020 13:15:15
- Last modified 21.11.2024 05:11:21
Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
CVE-2020-1772
- EPSS 0.59%
- Published 27.03.2020 13:15:15
- Last modified 21.11.2024 05:11:21
It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and pri...
CVE-2020-10969
- EPSS 1.4%
- Published 26.03.2020 13:15:13
- Last modified 21.11.2024 04:56:28
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
CVE-2020-10968
- EPSS 5.37%
- Published 26.03.2020 13:15:12
- Last modified 21.11.2024 04:56:28
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
CVE-2020-1957
- EPSS 86.1%
- Published 25.03.2020 16:15:19
- Last modified 21.11.2024 05:11:44
Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
CVE-2020-10942
- EPSS 0.04%
- Published 24.03.2020 22:15:12
- Last modified 21.11.2024 04:56:25
In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.
CVE-2020-6071
- EPSS 0.61%
- Published 24.03.2020 21:15:14
- Last modified 21.11.2024 05:35:02
An exploitable denial-of-service vulnerability exists in the resource record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the compression pointer is followed without checking for recursion, le...
CVE-2020-6072
- EPSS 2.2%
- Published 24.03.2020 21:15:14
- Last modified 21.11.2024 05:35:02
An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the rr_decode function's return value is not checked, leading to a double free that...
CVE-2020-6073
- EPSS 1.41%
- Published 24.03.2020 21:15:14
- Last modified 21.11.2024 05:35:02
An exploitable denial-of-service vulnerability exists in the TXT record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing the RDATA section in a TXT record in mDNS messages, multiple integer overflows can be triggered, leading to a d...