|
210701
|
5.5 |
MEDIUM
Local
|
whatsapp
|
whatsapp_business whatsapp
|
An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have resulted in an out-of-memory denial of service.…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-1903
|
2024-11-21 14:11 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210702
|
7.5 |
HIGH
Network
|
whatsapp
|
whatsapp_business whatsapp
|
A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from v2.20.35 to v2.20.49 could have been sent to the …
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-1902
|
2024-11-21 14:11 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210703
|
5.3 |
MEDIUM
Network
|
whatsapp
|
whatsapp
|
Receiving a large text message containing URLs in WhatsApp for iOS prior to v2.20.91.4 could have caused the application to freeze while processing the message.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-1901
|
2024-11-21 14:11 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210704
|
4.9 |
MEDIUM
Network
|
redhat
|
keycloak
|
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-1694
|
2024-11-21 14:11 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210705
|
7.5 |
HIGH
Network
|
redhat
|
wildfly_elytron decision_manager process_automation
|
A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an …
|
NVD-CWE-noinfo
|
CVE-2020-1748
|
2024-11-21 14:11 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210706
|
5.3 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform single_sign-on jboss_data_grid openshift_application_runtimes
|
The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.
|
NVD-CWE-Other
|
CVE-2020-1710
|
2024-11-21 14:11 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210707
|
8.1 |
HIGH
Network
|
facebook
|
hermes
|
An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c045e475fd71dc6 allows attackers to cause a denial of service attack or a potenti…
|
CWE-681
Incorrect Conversion between Numeric Types
|
CVE-2020-1913
|
2024-11-21 14:11 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210708
|
8.1 |
HIGH
Network
|
facebook
|
hermes
|
An out-of-bounds read/write vulnerability when executing lazily compiled inner generator functions in Facebook Hermes prior to commit 091835377369c8fd5917d9b87acffa721ad2a168 allows attackers to pote…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-1912
|
2024-11-21 14:11 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210709
|
7.5 |
HIGH
Network
|
linux redhat
|
linux_kernel enterprise_linux enterprise_mrg
|
A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. When an encrypted tunnel is created between two hosts, the ker…
|
-
|
CVE-2020-1749
|
2024-11-21 14:11 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210710
|
3.7 |
LOW
Network
|
openssl canonical debian oracle fujitsu
|
openssl ubuntu_linux debian_linux peoplesoft_enterprise_peopletools jd_edwards_world_security ethernet_switch_es2-64_firmware ethernet_switch_es2-72_firmware m10-1_firmware m1…
|
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based cipher…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-1968
|
2024-11-21 14:11 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|