|
209011
|
7.5 |
HIGH
Network
|
redhat
|
wildfly_elytron decision_manager process_automation
|
A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an …
|
NVD-CWE-noinfo
|
CVE-2020-1748
|
2024-11-21 14:11 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209012
|
5.3 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform single_sign-on jboss_data_grid openshift_application_runtimes
|
The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.
|
NVD-CWE-Other
|
CVE-2020-1710
|
2024-11-21 14:11 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209013
|
8.1 |
HIGH
Network
|
facebook
|
hermes
|
An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c045e475fd71dc6 allows attackers to cause a denial of service attack or a potenti…
|
CWE-681
Incorrect Conversion between Numeric Types
|
CVE-2020-1913
|
2024-11-21 14:11 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209014
|
8.1 |
HIGH
Network
|
facebook
|
hermes
|
An out-of-bounds read/write vulnerability when executing lazily compiled inner generator functions in Facebook Hermes prior to commit 091835377369c8fd5917d9b87acffa721ad2a168 allows attackers to pote…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-1912
|
2024-11-21 14:11 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209015
|
7.5 |
HIGH
Network
|
linux redhat
|
linux_kernel enterprise_linux enterprise_mrg
|
A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. When an encrypted tunnel is created between two hosts, the ker…
|
-
|
CVE-2020-1749
|
2024-11-21 14:11 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209016
|
3.7 |
LOW
Network
|
openssl canonical debian oracle fujitsu
|
openssl ubuntu_linux debian_linux peoplesoft_enterprise_peopletools jd_edwards_world_security ethernet_switch_es2-64_firmware ethernet_switch_es2-72_firmware m10-1_firmware m1…
|
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based cipher…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-1968
|
2024-11-21 14:11 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209017
|
9.8 |
CRITICAL
Network
|
facebook
|
hermes
|
A type confusion vulnerability when resolving properties of JavaScript objects with specially-crafted prototype chains in Facebook Hermes prior to commit fe52854cdf6725c2eaa9e125995da76e6ceb27da allo…
|
CWE-843
Type Confusion
|
CVE-2020-1911
|
2024-11-21 14:11 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209018
|
8.8 |
HIGH
Network
|
whatsapp
|
whatsapp whatsapp_business
|
A stack write overflow in WhatsApp for Android prior to v2.20.35, WhatsApp Business for Android prior to v2.20.20, WhatsApp for iPhone prior to v2.20.30, and WhatsApp Business for iPhone prior to v2.…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-1894
|
2024-11-21 14:11 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209019
|
9.8 |
CRITICAL
Network
|
whatsapp
|
whatsapp whatsapp_business
|
A user controlled parameter used in video call in WhatsApp for Android prior to v2.20.17, WhatsApp Business for Android prior to v2.20.7, WhatsApp for iPhone prior to v2.20.20, and WhatsApp Business …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-1891
|
2024-11-21 14:11 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209020
|
7.5 |
HIGH
Network
|
whatsapp
|
whatsapp whatsapp_business
|
A URL validation issue in WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 could have caused the recipient of a sticker message containing deliberately malfor…
|
CWE-20
Improper Input Validation
|
CVE-2020-1890
|
2024-11-21 14:11 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|