Search

Found 14,379 results in 632ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2021-39150 unknown FIX slesdebian debian 5y ago A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
CVE-2021-39151 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39152 unknown FIX slesdebian debian 5y ago A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
CVE-2021-39153 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39154 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-37714 unknown FIX slesdebian debian 5y ago Uncaught Exception in jsoup
CVE-2020-15522 unknown FIX debian debian sles 5y ago Timing based private key exposure in Bouncy Castle
CVE-2021-33192 unknown FIX debian debian 5y ago Cross-site scripting in Apache Jena Fuseki
CVE-2021-30640 unknown FIX slesdebian debian 5y ago A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This…
CVE-2021-33037 unknown FIX slesdebian debian 5y ago Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request…
CVE-2021-30639 unknown FIX debian debian 5y ago A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the e…
CVE-2021-35043 unknown FIX debian debian 5y ago Cross-site Scripting in OWASP AntiSamy
CVE-2021-36090 unknown FIX slesdebian debian 5y ago Improper Handling of Length Parameter Inconsistency in Compress
CVE-2021-35517 unknown FIX slesdebian debian 5y ago Improper Handling of Length Parameter Inconsistency in Compress
CVE-2021-35516 unknown FIX slesdebian debian 5y ago Improper Handling of Length Parameter Inconsistency in Compress
CVE-2021-35515 unknown FIX slesdebian debian 5y ago Excessive Iteration in Compress
CVE-2021-30129 unknown FIX debian debian 5y ago Buffer Overflow in Apache Mina SSHD
CVE-2019-25050 unknown FIX debian debian 5y ago netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_get_att_text) and in uffd_cleanup (called from netCDFDataset::~netCDFDataset and…
CVE-2021-34429 unknown 1.0 EXPFIX slesdebian debian 5y ago Encoded URIs can access WEB-INF directory in Eclipse Jetty
CVE-2021-38193 unknown FIX debian debian 5y ago An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870.
CVE-2021-38191 unknown FIX debian debian 5y ago An issue was discovered in the tokio crate before 1.8.1 for Rust. Upon a JoinHandle::abort, a Task may be dropped in the wrong thread.
CVE-2021-34428 unknown FIX slesdebian debian 5y ago SessionListener can prevent a session from being invalidated breaking logout
CVE-2021-32693 unknown FIX debian debian 5y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability related to firewall authentication is in Symfony starting with version 5.3.0 and prio…
CVE-2021-27807 unknown FIX slesdebian debian 5y ago Excessive Iteration Denial of Service in Apache PDFBox
CVE-2021-20220 unknown FIX debian debian 5y ago HTTP request smuggling in Undertow
CVE-2021-25122 unknown FIX slesdebian debian 5y ago When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body…
CVE-2021-26117 unknown FIX debian debian 5y ago Improper Authentication in Apache ActiveMQ and Apache Artemis
CVE-2021-23926 unknown FIX slesdebian debian 5y ago Improper Restriction of Recursive Entity References in Apache XMLBeans
CVE-2020-10688 unknown FIX debian debian 5y ago Cross-site scripting in RESTEasy
CVE-2021-31811 unknown FIX slesdebian debian 5y ago Uncontrolled memory consumption
CVE-2021-31812 unknown FIX slesdebian debian 5y ago Infinite Loop in Apache PDFBox
CVE-2021-28169 unknown FIX slesdebian debian 5y ago Jetty Utility Servlets ConcatServlet Double Decoding Information Disclosure Vulnerability
CVE-2020-12690 unknown FIX slesdebian debian 5y ago An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a key…
CVE-2020-25724 unknown FIX debian debian 5y ago Unsynchronized Access to Shared Data in a Multithreaded Context in RESTEasy
CVE-2020-14340 unknown FIX debian debian 5y ago Uncontrolled Resource Consumption in XNIO
CVE-2017-8761 unknown FIX debian debian 5y ago In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these log…
CVE-2020-10693 unknown FIX debian debian 5y ago Improper Input Validation in Hibernate Validator
CVE-2020-25633 unknown debian debian 5y ago Generation of Error Message Containing Sensitive Information in RESTEasy client
CVE-2014-9356 unknown FIX debian debian 5y ago Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or…
CVE-2021-29505 unknown FIX slesdebian debian 5y ago XStream is vulnerable to a Remote Command Execution attack
CVE-2021-29499 unknown FIX debian debian 5y ago SIF is an open source implementation of the Singularity Container Image Format. The `siftool new` command and func siftool.New() produce predictable UUID identifiers due to insecure randomness in the…
CVE-2019-13126 unknown FIX debian debian 5y ago An integer overflow in NATS Server before 2.0.2 allows a remote attacker to crash the server by sending a crafted request. If authentication is enabled, then the remote attacker must have first authe…
CVE-2020-9283 unknown 1.0 EXPFIX debian debian 5y ago golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accept…
CVE-2021-27906 unknown FIX slesdebian debian 5y ago Uncontrolled Memory Allocation in Apache PDFBox
CVE-2021-21424 unknown FIX debian debian 5y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling de…
CVE-2021-23368 unknown FIX debian debian 5y ago The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.
CVE-2021-28657 unknown slesdebian debian 5y ago Infinite loop in Apache Tika
CVE-2020-13933 unknown FIX debian debian 5y ago Authentication bypass in Apache Shiro
CVE-2020-1951 unknown FIX slesdebian debian 5y ago Infinite Loop in Apache Tika
CVE-2020-1950 unknown FIX slesdebian debian 5y ago Uncontrolled Resource Consumption in Apache Tika
CVE-2020-9489 unknown slesdebian debian 5y ago Missing Release of Memory after Effective Lifetime in Apache Tika
CVE-2020-1957 unknown FIX debian debian 5y ago Improper Authentication in Apache Shiro
CVE-2020-11989 unknown FIX debian debian 5y ago Improper Authentication in Apache Shiro
CVE-2020-5421 unknown FIX debian debian 5y ago Improper Input Validation in Spring Framework
CVE-2020-10687 unknown FIX debian debian 5y ago HTTP Request Smuggling in Undertow
CVE-2020-10705 unknown FIX debian debian 5y ago Allocation of Resources Without Limits or Throttling in Undertow
CVE-2020-10719 unknown FIX debian debian 5y ago HTTP Request Smuggling in Undertow
CVE-2020-26939 unknown FIX debian debian 5y ago Observable Differences in Behavior to Error Inputs in Bouncy Castle
CVE-2020-17510 unknown FIX debian debian 5y ago Authentication bypass in Apache Shiro
CVE-2021-23369 unknown FIX debian debian 5y ago Remote code execution in handlebars when compiling templates
CVE-2021-28163 unknown FIX slesdebian debian 5y ago Directory exposure in jetty
CVE-2021-28164 unknown 1.0 EXPFIX slesdebian debian 5y ago Authorization Before Parsing and Canonicalization in jetty
CVE-2021-21388 unknown FIX debian debian 5y ago systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has been discovered in versions of systeminformation prior to 5.6.4. The issue has…
CVE-2020-8908 unknown FIX slesdebian debian google 5y ago Information Disclosure in Guava
CVE-2021-21351 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21350 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21349 unknown FIX slesdebian debian 5y ago A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
CVE-2021-21348 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)
CVE-2021-21347 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21346 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21345 unknown FIX slesdebian debian 5y ago XStream is vulnerable to a Remote Command Execution attack
CVE-2021-21344 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21343 unknown FIX slesdebian debian 5y ago XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights
CVE-2021-21342 unknown FIX slesdebian debian 5y ago A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
CVE-2021-21341 unknown FIX slesdebian debian 5y ago XStream can cause a Denial of Service.
CVE-2021-25329 unknown FIX slesdebian debian 5y ago The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikel…
CVE-2020-13959 unknown FIX debian debian 5y ago Cross-site scripting (XSS) in Apache Velocity Tools
CVE-2020-27223 unknown FIX slesdebian debian 5y ago DOS vulnerability for Quoted Quality CSV headers
CVE-2020-25649 unknown FIX slesdebian debian 5y ago XML External Entity (XXE) Injection in Jackson Databind
CVE-2021-21315 unknown 1.5 KEVFIX debian debian 5y ago In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.
CVE-2021-21311 unknown 1.5 KEVFIX debian debian 5y ago Adminer contains a server-side request forgery vulnerability that, when exploited, allows a remote attacker to obtain potentially sensitive information.
CVE-2021-20190 unknown FIX slesdebian debian 5y ago Deserialization of untrusted data in jackson-databind
CVE-2020-26258 unknown FIX slesdebian debian 6y ago Server-Side Forgery Request can be activated unmarshalling with XStream
CVE-2020-26259 unknown FIX slesdebian debian 6y ago XStream vulnerable to an Arbitrary File Deletion on the local host when unmarshalling
CVE-2020-26274 unknown FIX debian debian 6y ago In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fixed in version 4.31.1 with a shell string sanitation fix.
CVE-2020-27218 unknown FIX slesdebian debian 6y ago Buffer not correctly recycled in Gzip Request inflation
CVE-2020-26245 unknown FIX debian debian 6y ago npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to avoid prototyper poll…
CVE-2020-26237 unknown FIX debian debian 6y ago Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerable to Prototype Pollution. A malicious HTML code block can be crafted that will …
CVE-2020-26217 unknown FIX slesdebian debian 6y ago XStream can be used for Remote Code Execution
CVE-2020-27216 unknown FIX debian debian 6y ago Local Temp Directory Hijacking Vulnerability
CVE-2020-35922 unknown FIX slesdebian debian 6y ago An issue was discovered in the mio crate before 0.7.6 for Rust. It has false expectations about the std::net::SocketAddr memory representation.
CVE-2020-26300 unknown FIX debian debian 6y ago systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is a command injection vulnerability. Problem was fix…
CVE-2020-7752 unknown FIX debian debian 6y ago This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execu…
CVE-2020-24660 unknown FIX debian debian 6y ago An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also af…
CVE-2020-15094 unknown FIX debian debian 6y ago In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X…
CVE-2019-17638 unknown FIX debian debian 6y ago Operation on a Resource after Expiration or Release in Jetty Server
CVE-2019-13990 unknown FIX slesdebian debian 6y ago XML external entity injection in Terracotta Quartz Scheduler
CVE-2017-7957 unknown FIX slesdebian debian 6y ago Denial of service in XStream
CVE-2016-3674 unknown FIX debian debian 6y ago XML External Entity Injection in XStream
CVE-2018-5968 unknown FIX slesdebian debian 6y ago Deserialization of Untrusted Data in jackson-databind