General-Purpose System Vulnerabilities
Vulnerabilities related to traditional IT systems, servers, and desktop applications.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2020-11713 | wolfSSL 4.3.0 has mulmod code in wc_ecc_mulmod_ex in ecc.c that does not properly resist timing side-channel attacks. | High (7.5) | 2020-04-12 | General Purpose |
| CVE-2020-11712 | Open Upload through 0.4.3 allows XSS via index.php?action=u and the filename field. | Medium (6.1) | 2020-04-12 | General Purpose |
| CVE-2020-11710 | An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces oth… | Critical (9.8) | 2020-04-12 | General Purpose |
| CVE-2020-11709 | cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, whi… | High (7.5) | 2020-04-12 | General Purpose |
| CVE-2020-11708 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. Privilege escalation can occur via the /ajax/Set… | Critical (9.8) | 2020-04-12 | General Purpose |