CVE-2018-14553
- EPSS 0.75%
- Published 11.02.2020 13:15:11
- Last modified 21.11.2024 03:49:18
gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).
CVE-2020-5529
- EPSS 2.09%
- Published 11.02.2020 12:15:21
- Last modified 21.11.2024 05:34:13
HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Andro...
CVE-2020-8840
- EPSS 8.16%
- Published 10.02.2020 21:56:10
- Last modified 21.11.2024 05:39:32
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
CVE-2020-7059
- EPSS 2.16%
- Published 10.02.2020 08:15:12
- Last modified 21.11.2024 05:36:35
When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead t...
CVE-2020-7060
- EPSS 6.4%
- Published 10.02.2020 08:15:12
- Last modified 21.11.2024 05:36:35
When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause function mbfl_filt_conv_big5_wchar to read past the alloc...
CVE-2019-15604
- EPSS 4.72%
- Published 07.02.2020 15:15:11
- Last modified 21.11.2024 04:29:06
Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate
CVE-2019-15605
- EPSS 32.25%
- Published 07.02.2020 15:15:11
- Last modified 21.11.2024 04:29:06
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
CVE-2019-15606
- EPSS 2.29%
- Published 07.02.2020 15:15:11
- Last modified 21.11.2024 04:29:07
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
CVE-2020-8608
- EPSS 1.81%
- Published 06.02.2020 17:15:14
- Last modified 21.11.2024 05:39:07
In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.
CVE-2016-9928
- EPSS 4.51%
- Published 06.02.2020 14:15:10
- Last modified 21.11.2024 03:02:01
MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XM...