Show filters
774 Total Results
Displaying 251-260 of 774
Sort by:
Attacker Value
Unknown
CVE-2021-1725
Disclosure Date: January 12, 2021 (last updated February 22, 2025)
Bot Framework SDK Information Disclosure Vulnerability
0
Attacker Value
Unknown
CVE-2020-28052
Disclosure Date: December 18, 2020 (last updated February 22, 2025)
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
0
Attacker Value
Unknown
CVE-2020-25649
Disclosure Date: December 03, 2020 (last updated February 22, 2025)
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
0
Attacker Value
Unknown
CVE-2020-28923
Disclosure Date: December 03, 2020 (last updated February 22, 2025)
An issue was discovered in Play Framework 2.8.0 through 2.8.4. Carefully crafted JSON payloads sent as a form field lead to Data Amplification. This affects users migrating from a Play version prior to 2.8.0 that used the Play Java API to serialize classes with protected or private fields to JSON.
0
Attacker Value
Unknown
CVE-2020-28206
Disclosure Date: December 02, 2020 (last updated February 22, 2025)
An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restriction of Excessive Authentication Attempts" vulnerability exists in the admin login form, allowing a remote user to enumerate users in the administrator group. This also allows brute-force attacks on the passwords of users not in the administrator group.
0
Attacker Value
Unknown
CVE-2020-27218
Disclosure Date: November 28, 2020 (last updated February 22, 2025)
In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.
0
Attacker Value
Unknown
CVE-2020-13954
Disclosure Date: November 12, 2020 (last updated February 22, 2025)
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.
0
Attacker Value
Unknown
CVE-2020-27196
Disclosure Date: November 06, 2020 (last updated February 22, 2025)
An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2. The body parsing of HTTP requests eagerly parses a payload given a Content-Type header. A deep JSON structure sent to a valid POST endpoint (that may or may not expect JSON payloads) causes a StackOverflowError and Denial of Service.
0
Attacker Value
Unknown
CVE-2020-26882
Disclosure Date: November 06, 2020 (last updated February 22, 2025)
In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input.
0
Attacker Value
Unknown
CVE-2020-26883
Disclosure Date: November 06, 2020 (last updated February 22, 2025)
In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents.
0