Show filters
440 Total Results
Displaying 241-250 of 440
Sort by:
Attacker Value
Unknown
CVE-2020-11663
Disclosure Date: April 15, 2020 (last updated February 21, 2025)
CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform open redirect attacks.
0
Attacker Value
Unknown
CVE-2020-11665
Disclosure Date: April 15, 2020 (last updated February 21, 2025)
CA API Developer Portal 4.3.1 and earlier handles loginRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks.
0
Attacker Value
Unknown
CVE-2020-11664
Disclosure Date: April 15, 2020 (last updated February 21, 2025)
CA API Developer Portal 4.3.1 and earlier handles homeRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks.
0
Attacker Value
Unknown
CVE-2020-11662
Disclosure Date: April 15, 2020 (last updated November 27, 2024)
CA API Developer Portal 4.3.1 and earlier handles requests insecurely, which allows remote attackers to exploit a Cross-Origin Resource Sharing flaw and access sensitive information.
0
Attacker Value
Unknown
CVE-2020-11661
Disclosure Date: April 15, 2020 (last updated November 27, 2024)
CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view and edit user data.
0
Attacker Value
Unknown
CVE-2020-11612
Disclosure Date: April 07, 2020 (last updated February 21, 2025)
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.
0
Attacker Value
Unknown
CVE-2020-2172
Disclosure Date: April 07, 2020 (last updated February 21, 2025)
Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
0
Attacker Value
Unknown
CVE-2020-9345
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of Service attack because the application doesn't limit the number of opened WebSocket sockets. If a victim visits an attacker-controlled website, this vulnerability can be exploited.
0
Attacker Value
Unknown
CVE-2020-9343
Disclosure Date: March 20, 2020 (last updated November 27, 2024)
An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of Service attack because the implementation doesn't limit the parsing of nested JSON structures. If a victim visits an attacker-controlled website, this vulnerability can be exploited via WebSocket data with a deeply nested JSON array.
0
Attacker Value
Unknown
CVE-2020-7606
Disclosure Date: March 15, 2020 (last updated February 21, 2025)
docker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the function 'exec(serviceName, cmd, fnStdout, fnStderr, fnExit)' uses the variable 'serviceName' which can be controlled by users without any sanitization.
0