Show filters
249 Total Results
Displaying 161-170 of 249
Sort by:
Attacker Value
Unknown
CVE-2020-8987
Disclosure Date: March 09, 2020 (last updated February 21, 2025)
Avast AntiTrack before 1.5.1.172 and AVG Antitrack before 2.0.0.178 proxies traffic to HTTPS sites but does not validate certificates, and thus a man-in-the-middle can host a malicious website using a self-signed certificate. No special action necessary by the victim using AntiTrack with "Allow filtering of HTTPS traffic for tracking detection" enabled. (This is the default configuration.)
0
Attacker Value
Unknown
CVE-2020-1935
Disclosure Date: February 24, 2020 (last updated February 21, 2025)
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
0
Attacker Value
Unknown
CVE-2019-17569
Disclosure Date: February 24, 2020 (last updated February 21, 2025)
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
0
Attacker Value
Unknown
CVE-2020-7912
Disclosure Date: January 30, 2020 (last updated February 21, 2025)
In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.
0
Attacker Value
Unknown
CVE-2020-7913
Disclosure Date: January 30, 2020 (last updated February 21, 2025)
JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description.
0
Attacker Value
Unknown
CVE-2019-0219
Disclosure Date: January 14, 2020 (last updated November 27, 2024)
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.
0
Attacker Value
Unknown
CVE-2019-10219
Disclosure Date: November 08, 2019 (last updated November 08, 2023)
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
0
Attacker Value
Unknown
CVE-2019-18369
Disclosure Date: October 31, 2019 (last updated November 27, 2024)
In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.
0
Attacker Value
Unknown
CVE-2019-12415
Disclosure Date: October 23, 2019 (last updated November 08, 2023)
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
0
Attacker Value
Unknown
CVE-2019-16171
Disclosure Date: October 02, 2019 (last updated November 27, 2024)
In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page.
0