Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-28442PUBLISHED: 2020-12-15All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function.
CVE-2020-35470PUBLISHED: 2020-12-15Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the information in the proxy protocol header. This affects situations with tcp-proxy as the network filter (not HTTP filters).
CVE-2020-35471PUBLISHED: 2020-12-15Envoy before 1.16.1 mishandles dropped and truncated datagrams, as demonstrated by a segmentation fault for a UDP packet size larger than 1500.
CVE-2020-35457PUBLISHED: 2020-12-14
** DISPUTED ** GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's position is "Realistically this is not a security issue. The standard pattern is for callers to provide a static list of option entries i...
CVE-2020-35460PUBLISHED: 2020-12-14common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.