Huge DDoS Attack Launched Against Cloudflare in Late June

Huge DDoS Attack Launched Against Cloudflare in Late June
Enterprise VulnerabilitiesFrom DHS/US-CERT's National Vulnerability Database CVE-2020-15001PUBLISHED: 2020-07-09

An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP application allows a user to set optional access codes on OTP slots. This access code is intended to prevent unauthorized changes to OTP configurations. The access code is not checked when u...

CVE-2020-15092PUBLISHED: 2020-07-09

In TimelineJS before version 3.7.0, some user data renders as HTML. An attacker could implement an XSS exploit with maliciously crafted content in a number of data fields. This risk is present whether the source data for the timeline is stored on Google Sheets or in a JSON configuration file. Most T...

CVE-2020-15093PUBLISHED: 2020-07-09

The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a minimum threshold of unique signatures before the metadata is considered valid. A ...

CVE-2020-15299PUBLISHED: 2020-07-09

A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is execu...

CVE-2020-4173
Support the originator by clicking the read the rest link below.