Show filters
249 Total Results
Displaying 151-160 of 249
Sort by:
Attacker Value
Unknown

CVE-2020-15817

Disclosure Date: August 08, 2020 (last updated November 28, 2024)
In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues.
Attacker Value
Unknown

CVE-2020-15818

Disclosure Date: August 08, 2020 (last updated November 28, 2024)
In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence.
Attacker Value
Unknown

CVE-2020-11993

Disclosure Date: August 07, 2020 (last updated February 21, 2025)
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers.
Attacker Value
Unknown

CVE-2020-13935

Disclosure Date: July 14, 2020 (last updated February 21, 2025)
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
Attacker Value
Unknown

CVE-2020-13934

Disclosure Date: July 14, 2020 (last updated February 21, 2025)
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.
Attacker Value
Unknown

CVE-2020-11693

Disclosure Date: April 22, 2020 (last updated November 27, 2024)
JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.
Attacker Value
Unknown

CVE-2020-11692

Disclosure Date: April 22, 2020 (last updated February 21, 2025)
In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators.
Attacker Value
Unknown

CVE-2020-11655

Disclosure Date: April 09, 2020 (last updated February 21, 2025)
SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.
Attacker Value
Unknown

CVE-2020-1927

Disclosure Date: April 02, 2020 (last updated February 21, 2025)
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
Attacker Value
Unknown

CVE-2020-1934

Disclosure Date: April 01, 2020 (last updated February 21, 2025)
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.