Show filters
774 Total Results
Displaying 301-310 of 774
Sort by:
Attacker Value
Unknown

CVE-2020-2866

Disclosure Date: April 15, 2020 (last updated November 27, 2024)
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload). Supported versions that are affected are 12.2.5-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.0 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
Attacker Value
Unknown

CVE-2020-2890

Disclosure Date: April 15, 2020 (last updated November 27, 2024)
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data as well as unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
Attacker Value
Unknown

CVE-2020-11612

Disclosure Date: April 07, 2020 (last updated February 21, 2025)
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.
Attacker Value
Unknown

CVE-2020-10594

Disclosure Date: March 15, 2020 (last updated February 21, 2025)
An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated token to obtain a new, working token via the refresh endpoint, because the blacklist protection mechanism is incompatible with the token-refresh feature. NOTE: drf-jwt is a fork of jpadilla/django-rest-framework-jwt, which is unmaintained.
Attacker Value
Unknown

CVE-2020-5203

Disclosure Date: March 11, 2020 (last updated February 21, 2025)
In Fat-Free Framework 3.7.1, attackers can achieve arbitrary code execution if developers choose to pass user controlled input (e.g., $_REQUEST, $_GET, or $_POST) to the framework's Clear method.
Attacker Value
Unknown

CVE-2020-1935

Disclosure Date: February 24, 2020 (last updated February 21, 2025)
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
Attacker Value
Unknown

CVE-2014-8089

Disclosure Date: February 17, 2020 (last updated February 21, 2025)
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
Attacker Value
Unknown

CVE-2016-5710

Disclosure Date: February 11, 2020 (last updated February 21, 2025)
NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.
Attacker Value
Unknown

CVE-2020-6174

Disclosure Date: February 05, 2020 (last updated February 21, 2025)
TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.
Attacker Value
Unknown

CVE-2020-8545

Disclosure Date: February 03, 2020 (last updated February 21, 2025)
Global.py in AIL framework 2.8 allows path traversal.