Show filters
871 Total Results
Displaying 261-270 of 871
Sort by:
Attacker Value
Unknown

CVE-2020-35884

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.
Attacker Value
Unknown

CVE-2019-25009

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness.
Attacker Value
Unknown

CVE-2020-35901

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the actix-http crate before 2.0.0-alpha.1 for Rust. There is a use-after-free in BodyStream.
Attacker Value
Unknown

CVE-2020-35669

Disclosure Date: December 24, 2020 (last updated February 22, 2025)
An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request.
Attacker Value
Unknown

CVE-2020-29596

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
MiniWeb HTTP server 0.8.19 allows remote attackers to cause a denial of service (daemon crash) via a long name for the first parameter in a POST request.
Attacker Value
Unknown

CVE-2020-13956

Disclosure Date: December 02, 2020 (last updated November 08, 2023)
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
Attacker Value
Unknown

CVE-2020-7780

Disclosure Date: November 27, 2020 (last updated February 22, 2025)
This affects the package com.softwaremill.akka-http-session:core_2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.12 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.11 before 0.5.11. For older versions, endpoints protected by randomTokenCsrfProtection could be bypassed with an empty X-XSRF-TOKEN header and an empty XSRF-TOKEN cookie.
Attacker Value
Unknown

CVE-2020-15239

Disclosure Date: October 06, 2020 (last updated February 22, 2025)
In xmpp-http-upload before version 0.4.0, when the GET method is attacked, attackers can read files which have a `.data` suffix and which are accompanied by a JSON file with the `.meta` suffix. This can lead to Information Disclosure and in some shared-hosting scenarios also to circumvention of authentication or other limitations on the outbound (GET) traffic. For example, in a scenario where a single server has multiple instances of the application running (with separate DATA_ROOT settings), an attacker who has knowledge about the directory structure is able to read files from any other instance to which the process has read access. If instances have individual authentication (for example, HTTP authentication via a reverse proxy, source IP based filtering) or other restrictions (such as quotas), attackers may circumvent those limits in such a scenario by using the Directory Traversal to retrieve data from the other instances. If the associated XMPP server (or anyone knowing the SECRE…
Attacker Value
Unknown

CVE-2020-25574

Disclosure Date: September 14, 2020 (last updated February 22, 2025)
An issue was discovered in the http crate before 0.1.20 for Rust. An integer overflow in HeaderMap::reserve() could result in denial of service (e.g., an infinite loop).
Attacker Value
Unknown

CVE-2020-24977

Disclosure Date: September 04, 2020 (last updated February 22, 2025)
GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.