CVE-2020-9547
- EPSS 43.14%
- Veröffentlicht 02.03.2020 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:40:50
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
CVE-2020-9548
- EPSS 62.02%
- Veröffentlicht 02.03.2020 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:40:50
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
CVE-2020-9546
- EPSS 2.33%
- Veröffentlicht 02.03.2020 04:15:10
- Zuletzt bearbeitet 21.11.2024 05:40:50
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
CVE-2020-5247
- EPSS 2.09%
- Veröffentlicht 28.02.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:33:45
In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response header, an attacker can use newline characters (i.e. `CR`, `LF` or`/r`, `/n`) to end the header and inject malicious content, such as ...
CVE-2019-10064
- EPSS 1.41%
- Veröffentlicht 28.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:19
hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, which results in inappropriate use of deterministic values. This was fixed in conjunction with CVE-201...
CVE-2020-9431
- EPSS 4.4%
- Veröffentlicht 27.02.2020 23:15:13
- Zuletzt bearbeitet 21.11.2024 05:40:37
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addressed in epan/dissectors/packet-lte-rrc.c by adjusting certain append operations.
CVE-2020-6383
- EPSS 24.92%
- Veröffentlicht 27.02.2020 23:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:37
Type confusion in V8 in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6384
- EPSS 2.43%
- Veröffentlicht 27.02.2020 23:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:37
Use after free in WebAudio in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6386
- EPSS 2.53%
- Veröffentlicht 27.02.2020 23:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:37
Use after free in speech in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6418
- EPSS 85.05%
- Veröffentlicht 27.02.2020 23:15:12
- Zuletzt bearbeitet 24.10.2025 21:04:01
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.