SFO Hit by Web Compromise

SFO Hit by Web Compromise
Enterprise VulnerabilitiesFrom DHS/US-CERT's National Vulnerability Database CVE-2020-11002PUBLISHED: 2020-04-10

dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template injection was identified in the self-validating feature enabling attackers to inject arbitrary Java EL expressions, leading to Remote Code Execution (RCE) vulnerability. If you ar...

CVE-2020-5303PUBLISHED: 2020-04-10

Tendermint before versions 0.33.3, 0.32.10, and 0.31.12 has a denial-of-service vulnerability. Tendermint does not limit the number of P2P connection requests. For each p2p connection, it allocates XXX bytes. Even though this memory is garbage collected once the connection is terminated (due to dupl...

CVE-2020-5330PUBLISHED: 2020-04-10

Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 and older and Dell EMC PowerEdge VRTX Switch Modules firmware versions 2.0.0.77 and older contain an information disclosure vulnerability. A remote unauthenticated attacker could e...

CVE-2020-5406PUBLISHED: 2020-04-10

VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes a version of PCF Autoscaling that writes database connection properties to its log, including database username and password. A malicious user with ac...

CVE-2020-6765PUBLISHED: 2020-04-10

D-Link DSL-GS225 J1 AU_1.0.4 devices allow an admin to execute OS commands by placing shell metacharacters after ..

Support the originator by clicking the read the rest link below.