Search Results (359890 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-7711 1 Goxmldsig Project 1 Goxmldsig 2024-11-21 7.5 High
This affects all versions of package github.com/russellhaering/goxmldsig. There is a crash on nil-pointer dereference caused by sending malformed XML signatures.
CVE-2020-7710 1 Safe-eval Project 1 Safe-eval 2024-11-21 8.1 High
This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host machine.
CVE-2020-7708 1 Irrelon 2 \@irrelon\/path, Irrelon-path 2024-11-21 9.8 Critical
The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushVal and pullVal functions.
CVE-2020-7707 1 Property-expr Project 1 Property-expr 2024-11-21 9.8 Critical
The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.
CVE-2020-7706 1 Connie-lang Project 1 Connie-lang 2024-11-21 9.8 Critical
The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie.
CVE-2020-7705 1 Mintegral 1 Mintegraladsdk 2024-11-21 7.1 High
This affects the package MintegralAdSDK from 0.0.0. The SDK distributed by the company contains malicious functionality that tracks any URL opened by the app and reports it back to the company, along with performing advertisement attribution fraud. Mintegral can remotely activate hooks on the UIApplication, openURL, SKStoreProductViewController, loadProductWithParameters and NSURLProtocol methods along with anti-debug and proxy detection protection. If those hooks are active MintegralAdSDK sends obfuscated data about every opened URL in an application to their servers. Note that the malicious functionality is enabled even if the SDK was not enabled to serve ads.
CVE-2020-7704 1 Linux-cmdline Project 1 Linux-cmdline 2024-11-21 9.8 Critical
The package linux-cmdline before 1.0.1 are vulnerable to Prototype Pollution via the constructor.
CVE-2020-7703 1 Nis-utils Project 1 Nis-utils 2024-11-21 9.8 Critical
All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function.
CVE-2020-7702 1 Templ8 Project 1 Templ8 2024-11-21 9.8 Critical
All versions of package templ8 are vulnerable to Prototype Pollution via the parse function.
CVE-2020-7701 1 Springtree 1 Madlib-object-utils 2024-11-21 9.8 Critical
madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.
CVE-2020-7700 1 Php.js Project 1 Php.js 2024-11-21 9.8 Critical
All versions of phpjs are vulnerable to Prototype Pollution via parse_str.
CVE-2020-7699 2 Express-fileupload Project, Netapp 2 Express-fileupload, Max Data 2024-11-21 7.5 High
This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.
CVE-2020-7698 1 Gerapy 1 Gerapy 2024-11-21 8.1 High
This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endpoint, isn’t being sanitized.
CVE-2020-7697 1 Mock2easy Project 1 Mock2easy 2024-11-21 9.8 Critical
This affects all versions of package mock2easy. a malicious user could inject commands through the _data variable: Affected Area require('../server/getJsonByCurl')(mock2easy, function (error, stdout) { if (error) { return res.json(500, error); } res.json(JSON.parse(stdout)); }, '', _data.interfaceUrl, query, _data.cookie,_data.interfaceType);
CVE-2020-7696 1 React-native-fast-image Project 1 React-native-fast-image 2024-11-21 5.3 Medium
This affects all versions of package react-native-fast-image. When an image with source={{uri: "...", headers: { host: "somehost.com", authorization: "..." }} is loaded, all other subsequent images will use the same headers, this can lead to signing credentials or other session tokens being leaked to other servers.
CVE-2020-7695 1 Encode 1 Uvicorn 2024-11-21 5.3 Medium
Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP headers. Attackers can exploit this to add arbitrary headers to HTTP responses, or even return an arbitrary response body, whenever crafted input is used to construct HTTP headers.
CVE-2020-7694 1 Encode 1 Uvicorn 2024-11-21 3.7 Low
This affects all versions of package uvicorn. The request logger provided by the package is vulnerable to ASNI escape sequence injection. Whenever any HTTP request is received, the default behaviour of uvicorn is to log its details to either the console or a log file. When attackers request crafted URLs with percent-encoded escape sequences, the logging component will log the URL after it's been processed with urllib.parse.unquote, therefore converting any percent-encoded characters into their single-character equivalent, which can have special meaning in terminal emulators. By requesting URLs with crafted paths, attackers can: * Pollute uvicorn's access logs, therefore jeopardising the integrity of such files. * Use ANSI sequence codes to attempt to interact with the terminal emulator that's displaying the logs (either in real time or from a file).
CVE-2020-7693 1 Sockjs Project 1 Sockjs 2024-11-21 5.3 Medium
Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.
CVE-2020-7692 2 Google, Redhat 3 Oauth Client Library For Java, Ocp Tools, Openshift 2024-11-21 7.4 High
PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that will be authorized. An attacker is able to obtain the authorization code using a malicious app on the client-side and use it to gain authorization to the protected resource. This affects the package com.google.oauth-client:google-oauth-client before 1.31.0.
CVE-2020-7691 1 Parall 1 Jspdf 2024-11-21 6.3 Medium
In all versions of the package jspdf, it is possible to use <<script>script> in order to go over the filtering regex.