CVEs (40)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Apache DebianEclipse+2 more17Blockchain Platform Communications Converged Application Server Service ControllerCommunications Offline Mediation Controller+14 moreJun 17, 2026 Nov 28, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto...Show more |
4C Ares Project FedoraprojectNodejs+1 more8Blockchain Platform C AresFedora+5 moreJun 17, 2026 Nov 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a D...Show more |
3Debian FasterxmlOracle26Agile Plm Application Testing SuiteAutovue For Agile Product Lifecycle Management+23 moreJun 17, 2026 Sep 17, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration. |
4Debian FasterxmlNetapp+1 more25Active Iq Unified Manager Agile PlmApplication Testing Suite+22 moreJun 17, 2026 Aug 25, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP). |
3Netapp NodejsOracle9Active Iq Unified Manager Banking Extensibility WorkbenchBlockchain Platform+6 moreJun 17, 2026 Jul 24, 2020 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0. |
2Lodash Oracle18Banking Corporate Lending Process Management Banking Credit Facilities Process ManagementBanking Extensibility Workbench+15 moreJun 17, 2026 Jul 15, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. |
7Apache CanonicalDebian+4 more18Agile Engineering Data Management Agile PlmBlockchain Platform+15 moreJun 17, 2026 Jul 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite lo...Show more |
5Mcafee OpenldapOpensuse+2 more5Blockchain Platform Enterprise LinuxLeap+2 moreJun 17, 2026 Jul 14, 2020 N/A· v4 4.2 MEDIUM· v3 4.0 MEDIUM· v2 libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This i...Show more |
2Nodejs Oracle5Banking Extensibility Workbench Blockchain PlatformGraalvm+2 moreJun 17, 2026 Jun 8, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0. |
6Debian FedoraprojectNghttp2+3 more10Banking Extensibility Workbench Blockchain PlatformDebian Linux+7 moreJun 17, 2026 Jun 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 byt...Show more |
8Debian DrupalFedoraproject+5 more70Agile Product Lifecycle Management For Process Agile Product Supplier Collaboration For ProcessApplication Testing Suite+67 moreJun 17, 2026 Apr 29, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted co...Show more |
7Debian DrupalFedoraproject+4 more52Active Iq Unified Manager Application ExpressApplication Testing Suite+49 moreJun 17, 2026 Apr 29, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(),...Show more |
2Dropwizard Oracle2Blockchain Platform Dropwizard ValidationJun 17, 2026 Feb 24, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions whe...Show more |
2Apache Oracle13Banking Corporate Lending Process Management Banking Credit Facilities Process ManagementBanking Liquidity Management+10 moreJun 17, 2026 Jan 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized...Show more |
6Apache DebianFedoraproject+3 more60Agile Plm Agile Product Lifecycle Management Integration PackApplication Testing Suite+57 moreJun 17, 2026 Aug 20, 2019 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, howev...Show more |
7Apple CanonicalDebian+4 more9Blockchain Platform Debian LinuxLeap+6 moreJun 17, 2026 Jul 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would o...Show more |
7Apple CanonicalDebian+4 more9Blockchain Platform Debian LinuxLeap+6 moreJun 17, 2026 Jul 26, 2019 N/A· v4 4.9 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant de...Show more |
4Mcafee OpenldapOpensuse+1 more4Blockchain Platform LeapOpenldap+1 moreMay 13, 2026 Dec 18, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to ca...Show more |
2Openldap Oracle2Blockchain Platform OpenldapMay 13, 2026 Sep 5, 2017 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID fil...Show more |
5Debian McafeeOpenldap+2 more10Blockchain Platform Debian LinuxEnterprise Linux Desktop+7 moreMay 13, 2026 May 29, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with...Show more |