Search

Found 14,368 results in 638ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2018-10237 unknown FIX slesdebian debian 6y ago Denial of Service in Google Guava
CVE-2017-7536 unknown FIX debian debian 6y ago Privilege Escalation in Hibernate Validator
CVE-2020-11612 unknown FIX slesdebian debian 6y ago Denial of Service in Netty
CVE-2018-15756 unknown FIX debian debian 6y ago Denial of Service in Spring Framework
CVE-2009-2625 unknown FIX debian debian 6y ago Denial of service in Apache Xerces2
CVE-2018-12023 unknown FIX debian debian 6y ago Deserialization of Untrusted Data
CVE-2019-17267 unknown FIX slesdebian debian 6y ago Improper Input Validation in jackson-databind
CVE-2020-10683 unknown FIX slesdebian debian 6y ago dom4j allows External Entities by default which might enable XXE attacks
CVE-2020-1941 unknown FIX debian debian 6y ago Apache ActiveMQ webconsole admin GUI is open to XSS
CVE-2020-1953 unknown FIX debian debian 6y ago Remote code execution in Apache Commons Configuration
CVE-2019-14893 unknown FIX debian debian 6y ago Polymorphic deserialization of malicious object in jackson-databind
CVE-2019-14892 unknown FIX debian debian 6y ago Polymorphic deserialization of malicious object in jackson-databind
CVE-2020-10968 unknown FIX debian debian 6y ago jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2020-11111 unknown FIX debian debian 6y ago jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2020-10969 unknown FIX debian debian 6y ago jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2020-11620 unknown FIX debian debian 6y ago jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2020-5275 unknown FIX debian debian 6y ago In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides …
CVE-2020-5274 unknown FIX debian debian 6y ago In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. In addition, the stacktrace were displayed even …
CVE-2020-5255 unknown FIX debian debian 6y ago In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format defined in the `Accept` header of the r…
CVE-2019-17569 unknown FIX debian debian 6y ago The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were …
CVE-2020-7238 unknown FIX slesdebian debian 6y ago HTTP Request Smuggling in Netty
CVE-2019-20444 unknown FIX slesdebian debian 6y ago HTTP Request Smuggling in Netty
CVE-2019-20445 unknown FIX slesdebian debian 6y ago HTTP Request Smuggling in Netty
CVE-2019-17558 unknown 2.5 KEVEXP debian debian 6y ago The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.
CVE-2019-10911 unknown FIX debian debian 6y ago In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with…
CVE-2019-10912 unknown FIX debian debian 6y ago In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this coul…
CVE-2019-11325 unknown FIX debian debian 6y ago An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrar…
CVE-2019-10172 unknown FIX debian debian 6y ago Improper Restriction of XML External Entity Reference in jackson-mapper-asl
CVE-2019-12422 unknown debian debian 6y ago Improper input validation in Apache Shiro
CVE-2019-10782 unknown FIX debian debian 6y ago XML external entity (XXE) processing ('external-parameter-entities' feature was not fully disabled))
CVE-2020-5397 unknown FIX debian debian 7y ago CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux
CVE-2020-5398 unknown FIX debian debian 7y ago RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application
CVE-2019-10219 unknown FIX debian debian 7y ago The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks
CVE-2019-12418 unknown FIX slesdebian debian 7y ago When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration f…
CVE-2019-17563 unknown FIX slesdebian debian 7y ago When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The wind…
CVE-2019-17632 unknown FIX debian debian 7y ago Unescaped exception messages in error responses in Jetty
CVE-2019-10913 unknown FIX debian debian 7y ago In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted inpu…
CVE-2019-18886 unknown FIX debian debian 7y ago An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling depending on whether the user existed when making unauthor…
CVE-2019-18888 unknown FIX debian debian 7y ago An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIM…
CVE-2019-18889 unknown FIX debian debian 7y ago An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is rel…
CVE-2019-10212 unknown FIX debian debian 7y ago Potential to access user credentials from the log files when debug logging enabled
CVE-2019-10910 unknown FIX debian debian 7y ago In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code exec…
CVE-2019-10909 unknown FIX debian debian 7y ago In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. Th…
CVE-2019-17359 unknown FIX debian debian 7y ago Out-of-Memory Error in Bouncy Castle Crypto
CVE-2019-17545 unknown FIX debian debian 7y ago GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.
CVE-2019-16869 unknown FIX slesdebian debian 7y ago HTTP Request Smuggling in Netty
CVE-2019-12402 unknown FIX debian debian 7y ago Denial of Service in Apache Commons Compress
CVE-2019-10753 unknown FIX debian debian 7y ago Incorrect Resource Transfer Between Spheres in eclipse-wtp
CVE-2019-12400 unknown FIX debian debian 7y ago Improper input validation in Apache Santuario XML Security for Java
CVE-2019-16137 unknown FIX debian debian 7y ago An issue was discovered in the spin crate before 0.5.2 for Rust, when RwLock is used. Because memory ordering is mishandled, two writers can acquire the lock at the same time, violating mutual exclus…
CVE-2019-10088 unknown FIX slesdebian debian 7y ago Allocation of Resources Without Limits or Throttling in Apache Tika
CVE-2019-10093 unknown FIX slesdebian debian 7y ago Allocation of Resources Without Limits or Throttling in Apache Tika
CVE-2019-10094 unknown FIX slesdebian debian 7y ago Allocation of Resources Without Limits or Throttling in Apache Tika
CVE-2019-10184 unknown FIX debian debian 7y ago Undertow Missing Authorization when requesting a protected directory without trailing slash
CVE-2019-14439 unknown FIX debian debian 7y ago Deserialization of untrusted data in FasterXML jackson-databind
CVE-2019-14379 unknown FIX slesdebian debian 7y ago Deserialization of untrusted data in FasterXML jackson-databind
CVE-2015-7559 unknown FIX debian debian 7y ago Improper Input Validation and Missing Authentication for Critical Function in Apache ActiveMQ
CVE-2019-0193 unknown 1.5 KEVFIX debian debian 7y ago The optional Apache Solr module DataImportHandler contains a code injection vulnerability.
CVE-2019-10173 unknown FIX slesdebian debian 7y ago Deserialization of Untrusted Data and Code Injection in xstream
CVE-2018-11307 unknown FIX debian debian 7y ago Deserialization of Untrusted Data in jackson-databind
CVE-2019-0228 unknown FIX debian debian 7y ago Vulnerability that affects org.apache.pdfbox:pdfbox
CVE-2019-10072 unknown FIX slesdebian debian 7y ago The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDA…
CVE-2019-3888 unknown FIX debian debian 7y ago Credential exposure through log files in Undertow
CVE-2019-0221 unknown 1.0 EXPFIX slesdebian debian 7y ago The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by…
CVE-2019-0201 unknown FIX slesdebian debian 7y ago Access control bypass in Apache ZooKeeper
CVE-2013-7285 unknown 1.0 EXPFIX slesdebian debian 7y ago Command Injection in Xstream
CVE-2019-0227 unknown 1.0 EXP debian debian sles 7y ago Server Side Request Forgery in Apache Axis
CVE-2019-15542 unknown FIX debian debian 7y ago An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization.
CVE-2019-10246 unknown FIX debian debian 7y ago Information Exposure vulnerability in Eclipse Jetty
CVE-2019-10247 unknown FIX debian debian 7y ago Installation information leak in Eclipse Jetty
CVE-2019-10241 unknown FIX debian debian 7y ago Cross-site Scripting in Eclipse Jetty
CVE-2019-5427 unknown FIX debian debian sles 7y ago Billion laughs attack in c3p0
CVE-2019-0232 unknown 1.0 EXPFIX debian debian 7y ago When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a b…
CVE-2019-0222 unknown FIX debian debian 7y ago Improper Control of Generation of Code ('Code Injection') in org.apache.activemq:activemq-client
CVE-2019-10648 unknown FIX debian debian 7y ago Robocode through 1.9.3.5 allows remote attackers to cause external service interaction (DNS), as demonstrated by a query for a unique subdomain name within an attacker-controlled DNS zone, because of…
CVE-2018-12545 unknown FIX debian debian 7y ago Uncontrolled Resource Consumption in org.eclipse.jetty:jetty-server
CVE-2018-12022 unknown FIX debian debian 7y ago jackson-databind Deserialization of Untrusted Data vulnerability
CVE-2018-1324 unknown FIX debian debian 7y ago Apache Commons Compress vulnerable to denial of service due to infinite loop
CVE-2017-3164 unknown debian debian 7y ago Server-Side Request Forgery (SSRF) in org.apache.solr:solr-core
CVE-2019-0192 unknown FIX debian debian 7y ago Critical severity vulnerability that affects org.apache.solr:solr-core
CVE-2019-9658 unknown FIX debian debian 7y ago Moderate severity vulnerability that affects com.puppycrawl.tools:checkstyle
CVE-2019-5418 unknown 2.5 KEVEXPFIX slesdebian debian 7y ago Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can cause arbitrary files on the target server…
CVE-2019-0187 unknown debian debian 7y ago Unauthenticated Remote Code Execution in Apache JMeter
CVE-2018-1320 unknown FIX debian debian 8y ago Improper Input Validation in Apache Thrift
CVE-2018-11798 unknown FIX debian debian 8y ago Apache Thrift Node.js static web server sandbox escape
CVE-2018-20433 unknown FIX debian debian sles 8y ago XML External Entity Reference in mchange:c3p0
CVE-2018-14719 unknown FIX debian debian 8y ago Arbitrary Code Execution in jackson-databind
CVE-2018-14720 unknown FIX debian debian 8y ago XML External Entity Reference (XXE) in jackson-databind
CVE-2018-14721 unknown FIX debian debian 8y ago Server-Side Request Forgery (SSRF) in jackson-databind
CVE-2018-19362 unknown FIX debian debian 8y ago com.fasterxml.jackson.core:jackson-databind vulnerable to Deserialization of Untrusted Data
CVE-2018-19361 unknown FIX debian debian 8y ago Deserialization of Untrusted Data in jackson-databind
CVE-2018-19360 unknown FIX debian debian 8y ago Deserialization of Untrusted Data in jackson-databind due to polymorphic deserialization
CVE-2018-14718 unknown FIX debian debian 8y ago Arbitrary Code Execution in jackson-databind
CVE-2018-17197 unknown FIX slesdebian debian 8y ago Apache Tika Denial of Service due to Infinite Loop in Tika's SQLite3Parser
CVE-2018-17187 unknown FIX debian debian 8y ago Improper Certificate Validation in proton-j
CVE-2018-1337 unknown FIX debian debian 8y ago In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connec…
CVE-2018-8006 unknown FIX debian debian 8y ago Apache ActiveMQ web console vulnerable to Cross-site Scripting
CVE-2017-2666 unknown FIX debian debian 8y ago Undertow-core vulnerable to HTTP Request Smuggling
CVE-2017-2670 unknown FIX debian debian 8y ago Moderate severity vulnerability that affects io.undertow:undertow-core
CVE-2018-10936 unknown FIX slesdebian debian 8y ago Moderate severity vulnerability that affects org.postgresql:pgjdbc-aggregate