Show filters
871 Total Results
Displaying 261-270 of 871
Sort by:
Attacker Value
Unknown
CVE-2020-35884
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.
0
Attacker Value
Unknown
CVE-2019-25009
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness.
0
Attacker Value
Unknown
CVE-2020-35901
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the actix-http crate before 2.0.0-alpha.1 for Rust. There is a use-after-free in BodyStream.
0
Attacker Value
Unknown
CVE-2020-35669
Disclosure Date: December 24, 2020 (last updated February 22, 2025)
An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request.
0
Attacker Value
Unknown
CVE-2020-29596
Disclosure Date: December 21, 2020 (last updated February 22, 2025)
MiniWeb HTTP server 0.8.19 allows remote attackers to cause a denial of service (daemon crash) via a long name for the first parameter in a POST request.
0
Attacker Value
Unknown
CVE-2020-13956
Disclosure Date: December 02, 2020 (last updated November 08, 2023)
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
0
Attacker Value
Unknown
CVE-2020-7780
Disclosure Date: November 27, 2020 (last updated February 22, 2025)
This affects the package com.softwaremill.akka-http-session:core_2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.12 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.11 before 0.5.11. For older versions, endpoints protected by randomTokenCsrfProtection could be bypassed with an empty X-XSRF-TOKEN header and an empty XSRF-TOKEN cookie.
0
Attacker Value
Unknown
CVE-2020-15239
Disclosure Date: October 06, 2020 (last updated February 22, 2025)
In xmpp-http-upload before version 0.4.0, when the GET method is attacked, attackers can read files which have a `.data` suffix and which are accompanied by a JSON file with the `.meta` suffix. This can lead to Information Disclosure and in some shared-hosting scenarios also to circumvention of authentication or other limitations on the outbound (GET) traffic. For example, in a scenario where a single server has multiple instances of the application running (with separate DATA_ROOT settings), an attacker who has knowledge about the directory structure is able to read files from any other instance to which the process has read access. If instances have individual authentication (for example, HTTP authentication via a reverse proxy, source IP based filtering) or other restrictions (such as quotas), attackers may circumvent those limits in such a scenario by using the Directory Traversal to retrieve data from the other instances. If the associated XMPP server (or anyone knowing the SECRE…
0
Attacker Value
Unknown
CVE-2020-25574
Disclosure Date: September 14, 2020 (last updated February 22, 2025)
An issue was discovered in the http crate before 0.1.20 for Rust. An integer overflow in HeaderMap::reserve() could result in denial of service (e.g., an infinite loop).
0
Attacker Value
Unknown
CVE-2020-24977
Disclosure Date: September 04, 2020 (last updated February 22, 2025)
GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.
0