Search Results (2870 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-36230 4 Apache, Apple, Debian and 1 more 5 Bookkeeper, Mac Os X, Macos and 2 more 2024-11-21 7.5 High
A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.
CVE-2020-36222 3 Apple, Debian, Openldap 4 Mac Os X, Macos, Debian Linux and 1 more 2024-11-21 7.5 High
A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service.
CVE-2020-36124 1 Paxtechnology 1 Paxstore 2024-11-21 6.5 Medium
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise the private keys of a JWT token and reuse them to manipulate the access tokens to access the platform as any desired user (clients and administrators).
CVE-2020-35604 1 Kronos 1 Web Time And Attendance 2024-11-21 9.8 Critical
An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used.
CVE-2020-35358 1 Domainmod 1 Domainmod 2024-11-21 9.8 Critical
DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed password and old sessions in any other browser or device do not expire and remain active. Such flaws frequently give attackers unauthorized access to some system data or functionality.
CVE-2020-35123 1 Zimbra 1 Collaboration 2024-11-21 6.5 Medium
In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks. This has been fixed in Zimbra Collaboration Suite Network edition 9.0.0 Patch 10 and 8.8.15 Patch 17.
CVE-2020-2324 1 Jenkins 1 Cvs 2024-11-21 7.5 High
Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2305 2 Jenkins, Redhat 2 Mercurial, Openshift 2024-11-21 6.5 Medium
Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2304 2 Jenkins, Redhat 2 Subversion, Openshift 2024-11-21 6.5 Medium
Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2284 1 Jenkins 1 Liquibase Runner 2024-11-21 7.1 High
Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2247 1 Jenkins 1 Klocwork Analysis 2024-11-21 6.5 Medium
Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2245 1 Jenkins 1 Valgrind 2024-11-21 7.1 High
Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2178 1 Jenkins 1 Parasoft Findings 2024-11-21 7.1 High
Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2171 1 Jenkins 1 Rapiddeploy 2024-11-21 8.8 High
Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2144 1 Jenkins 1 Rundeck 2024-11-21 7.1 High
Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2138 1 Jenkins 1 Cobertura 2024-11-21 7.1 High
Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2120 1 Jenkins 1 Fitnesse 2024-11-21 8.8 High
Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2115 1 Jenkins 1 Nunit 2024-11-21 8.8 High
Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2108 1 Jenkins 1 Websphere Deployer 2024-11-21 7.6 High
Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Job/Configure permissions.
CVE-2020-2092 1 Jenkins 1 Robot Framework 2024-11-21 8.8 High
Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing users with Job/Configure to have Jenkins parse crafted XML documents.