CVE-2020-7238
- EPSS 0.74%
- Veröffentlicht 27.01.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:36:53
Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869...
CVE-2015-9541
- EPSS 0.9%
- Veröffentlicht 24.01.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 02:40:53
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
CVE-2014-4172
- EPSS 6.74%
- Veröffentlicht 24.01.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 02:09:38
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitr...
CVE-2019-17570
- EPSS 70.52%
- Veröffentlicht 23.01.2020 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:33
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apa...
CVE-2015-5745
- EPSS 1.92%
- Veröffentlicht 23.01.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 02:33:45
Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message.
CVE-2015-5239
- EPSS 5.06%
- Veröffentlicht 23.01.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 02:32:37
Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.
CVE-2015-5278
- EPSS 1.85%
- Veröffentlicht 23.01.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 02:32:42
The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.
CVE-2019-18222
- EPSS 0.08%
- Veröffentlicht 23.01.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:52
The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks.
CVE-2019-20388
- EPSS 0.56%
- Veröffentlicht 21.01.2020 23:15:13
- Zuletzt bearbeitet 17.12.2025 22:15:55
xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.
CVE-2020-7595
- EPSS 0.47%
- Veröffentlicht 21.01.2020 23:15:13
- Zuletzt bearbeitet 03.12.2025 16:15:54
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.