|
208411
|
7.8 |
HIGH
Local
|
whatsapp
|
whatsapp_business whatsapp
|
A buffer overflow in WhatsApp for Android prior to v2.20.130 and WhatsApp Business for Android prior to v2.20.46 could have allowed an out-of-bounds write when processing malformed local videos with …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-1906
|
2024-11-21 14:11 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208412
|
3.3 |
LOW
Local
|
whatsapp
|
whatsapp
|
Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen …
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-1905
|
2024-11-21 14:11 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208413
|
5.5 |
MEDIUM
Local
|
whatsapp
|
whatsapp_business whatsapp
|
A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwriting files when sending specially craft…
|
CWE-22
Path Traversal
|
CVE-2020-1904
|
2024-11-21 14:11 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208414
|
5.5 |
MEDIUM
Local
|
whatsapp
|
whatsapp_business whatsapp
|
An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have resulted in an out-of-memory denial of service.…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-1903
|
2024-11-21 14:11 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208415
|
7.5 |
HIGH
Network
|
whatsapp
|
whatsapp_business whatsapp
|
A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from v2.20.35 to v2.20.49 could have been sent to the …
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-1902
|
2024-11-21 14:11 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208416
|
5.3 |
MEDIUM
Network
|
whatsapp
|
whatsapp
|
Receiving a large text message containing URLs in WhatsApp for iOS prior to v2.20.91.4 could have caused the application to freeze while processing the message.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-1901
|
2024-11-21 14:11 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208417
|
4.9 |
MEDIUM
Network
|
redhat
|
keycloak
|
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-1694
|
2024-11-21 14:11 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208418
|
7.5 |
HIGH
Network
|
redhat
|
wildfly_elytron decision_manager process_automation
|
A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an …
|
NVD-CWE-noinfo
|
CVE-2020-1748
|
2024-11-21 14:11 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208419
|
5.3 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform single_sign-on jboss_data_grid openshift_application_runtimes
|
The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.
|
NVD-CWE-Other
|
CVE-2020-1710
|
2024-11-21 14:11 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208420
|
8.1 |
HIGH
Network
|
facebook
|
hermes
|
An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c045e475fd71dc6 allows attackers to cause a denial of service attack or a potenti…
|
CWE-681
Incorrect Conversion between Numeric Types
|
CVE-2020-1913
|
2024-11-21 14:11 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|