Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2020-36179 |
|
Unsafe Deserialization in apache (CVE-2020-36179)
vulnerability in apache (CVE-2020-36179). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36180 |
|
Unsafe Deserialization in apache (CVE-2020-36180)
vulnerability in apache (CVE-2020-36180). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36182 |
|
Unsafe Deserialization in apache (CVE-2020-36182)
vulnerability in apache (CVE-2020-36182). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36184 |
|
Unsafe Deserialization in apache (CVE-2020-36184)
vulnerability in apache (CVE-2020-36184). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36185 |
|
Unsafe Deserialization in apache (CVE-2020-36185)
vulnerability in apache (CVE-2020-36185). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36186 |
|
Unsafe Deserialization in apache (CVE-2020-36186)
vulnerability in apache (CVE-2020-36186). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36187 |
|
Unsafe Deserialization in apache (CVE-2020-36187)
vulnerability in apache (CVE-2020-36187). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36188 |
|
Unsafe Deserialization in fasterxml (CVE-2020-36188)
vulnerability in fasterxml (CVE-2020-36188). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36189 |
|
Unsafe Deserialization in fasterxml (CVE-2020-36189)
vulnerability in fasterxml (CVE-2020-36189). Successful exploitation can lead to full system takeover.
|
| CVE-2020-36181 |
|
Unsafe Deserialization in apache (CVE-2020-36181)
vulnerability in apache (CVE-2020-36181). Successful exploitation can lead to full system takeover.
|
| CVE-2020-35728 |
|
Unsafe Deserialization in apache (CVE-2020-35728)
vulnerability in apache (CVE-2020-35728). Successful exploitation can lead to full system takeover.
|
| CVE-2020-35490 |
|
Unsafe Deserialization in apache (CVE-2020-35490)
vulnerability in apache (CVE-2020-35490). Successful exploitation can lead to full system takeover.
|
| CVE-2020-35491 |
|
Unsafe Deserialization in apache (CVE-2020-35491)
vulnerability in apache (CVE-2020-35491). Successful exploitation can lead to full system takeover.
|
| CVE-2020-17103 |
|
, aka 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability'. This CVE ID...
, aka 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability'. This CVE ID...
|
| CVE-2020-25649 |
|
XXE (XML External Entity) in fasterxml (CVE-2020-25649)
vulnerability in fasterxml (CVE-2020-25649). Data can be tampered with by attackers.
|
| CVE-2020-24750 |
|
Unsafe Deserialization in fasterxml (CVE-2020-24750)
vulnerability in fasterxml (CVE-2020-24750). Successful exploitation can lead to full system takeover.
|
| CVE-2020-24616 |
|
Unsafe Deserialization in fasterxml (CVE-2020-24616)
vulnerability in fasterxml (CVE-2020-24616). Successful exploitation can lead to full system takeover.
|
| CVE-2020-14195 |
|
Unsafe Deserialization in fasterxml (CVE-2020-14195)
vulnerability in fasterxml (CVE-2020-14195). Successful exploitation can lead to full system takeover.
|
| CVE-2020-14061 |
|
Unsafe Deserialization in fasterxml (CVE-2020-14061)
vulnerability in fasterxml (CVE-2020-14061). Successful exploitation can lead to full system takeover.
|
| CVE-2020-14062 |
|
Unsafe Deserialization in apache (CVE-2020-14062)
vulnerability in apache (CVE-2020-14062). Successful exploitation can lead to full system takeover.
|
| CVE-2020-9484 |
|
Unsafe Deserialization in org.apache.tomcat:tomcat-catalina (CVE-2020-9484)
vulnerability in org.apache.tomcat:tomcat-catalina (CVE-2020-9484). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.0.104` or later.
|
| CVE-2020-11619 |
|
Unsafe Deserialization in fasterxml (CVE-2020-11619)
vulnerability in fasterxml (CVE-2020-11619). Successful exploitation can lead to full system takeover.
|
| CVE-2020-11111 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, an...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
|
| CVE-2020-11112 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/common...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
|
| CVE-2020-11113 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
|
| CVE-2020-10969 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
|
| CVE-2020-10968 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
|
| CVE-2020-10672 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
|
| CVE-2020-10673 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
|
| CVE-2011-4088 |
|
ABRT might allow attackers to obtain sensitive information from crash reports.
ABRT might allow attackers to obtain sensitive information from crash reports.
|
| CVE-2019-19378 |
|
Out-of-Bounds Write in c (CVE-2019-19378)
out-of-bounds write in c (CVE-2019-19378). Successful exploitation can lead to full system takeover.
|
| CVE-2019-18197 |
|
Use-After-Free in nokogiri (CVE-2019-18197)
vulnerability in nokogiri (CVE-2019-18197). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.10.5` or later.
|
| CVE-2019-10086 |
|
Unsafe Deserialization in apache (CVE-2019-10086)
vulnerability in apache (CVE-2019-10086). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-15756 |
|
Vulnerability in spring (CVE-2018-15756)
vulnerability in spring (CVE-2018-15756). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-10902 |
|
Vulnerability in c (CVE-2018-10902)
vulnerability in c (CVE-2018-10902). Successful exploitation can lead to full system takeover.
|
| CVE-2018-9988 |
|
Out-of-Bounds Read in arm (CVE-2018-9988)
vulnerability in arm (CVE-2018-9988). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-9989 |
|
Out-of-Bounds Read in arm (CVE-2018-9989)
vulnerability in arm (CVE-2018-9989). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-1862 |
|
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve...
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve...
|
| CVE-2017-17997 |
|
Vulnerability in c (CVE-2017-17997)
vulnerability in c (CVE-2017-17997). Risk of unauthorized operations or information disclosure.
|
| CVE-2014-8119 |
|
Vulnerability in dos (CVE-2014-8119)
vulnerability in dos (CVE-2014-8119). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-8008 |
|
Vulnerability in mediawiki (CVE-2015-8008)
vulnerability in mediawiki (CVE-2015-8008). Confidential information can be exposed externally.
|
| CVE-2016-6914 |
|
Vulnerability in ui (CVE-2016-6914)
vulnerability in ui (CVE-2016-6914). Successful exploitation can lead to full system takeover.
|
| CVE-2017-7156 |
|
Buffer Overflow in dos (CVE-2017-7156)
vulnerability in dos (CVE-2017-7156). Successful exploitation can lead to full system takeover.
|
| CVE-2017-7157 |
|
Buffer Overflow in dos (CVE-2017-7157)
vulnerability in dos (CVE-2017-7157). Successful exploitation can lead to full system takeover.
|
| CVE-2017-7160 |
|
Buffer Overflow in dos (CVE-2017-7160)
vulnerability in dos (CVE-2017-7160). Successful exploitation can lead to full system takeover.
|
| CVE-2017-17912 |
|
Out-of-Bounds Read in c (CVE-2017-17912)
vulnerability in c (CVE-2017-17912). Successful exploitation can lead to full system takeover.
|
| CVE-2017-17913 |
|
Out-of-Bounds Read in c (CVE-2017-17913)
vulnerability in c (CVE-2017-17913). Successful exploitation can lead to full system takeover.
|
| CVE-2017-17915 |
|
Out-of-Bounds Read in c (CVE-2017-17915)
vulnerability in c (CVE-2017-17915). Successful exploitation can lead to full system takeover.
|
| CVE-2017-17935 |
|
Out-of-Bounds Read in c (CVE-2017-17935)
vulnerability in c (CVE-2017-17935). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-17879 |
|
Out-of-Bounds Read in c (CVE-2017-17879)
vulnerability in c (CVE-2017-17879). Successful exploitation can lead to full system takeover.
|