CVE-2021-21409
- EPSS 4.98%
- Published 30.03.2021 15:15:14
- Last modified 21.11.2024 05:48:17
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerabi...
CVE-2021-20289
- EPSS 0.09%
- Published 26.03.2021 17:15:13
- Last modified 21.11.2024 05:46:17
A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JA...
CVE-2021-21295
- EPSS 0.96%
- Published 09.03.2021 19:15:12
- Last modified 21.11.2024 05:47:57
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerabi...
CVE-2021-20328
- EPSS 0.13%
- Published 25.02.2021 17:15:28
- Last modified 21.11.2024 05:46:23
Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in combination with a privileged network position active M...
CVE-2020-28491
- EPSS 0.13%
- Published 18.02.2021 16:15:13
- Last modified 21.11.2024 05:22:53
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
CVE-2021-21290
- EPSS 0.02%
- Published 08.02.2021 20:15:12
- Last modified 21.11.2024 05:47:56
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems inv...
CVE-2020-8908
- EPSS 0.01%
- Published 10.12.2020 23:15:13
- Last modified 21.11.2024 05:39:40
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By defau...
CVE-2020-25649
- EPSS 0.01%
- Published 03.12.2020 17:15:12
- Last modified 21.11.2024 05:18:20
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
CVE-2020-13956
- EPSS 0.51%
- Published 02.12.2020 17:15:14
- Last modified 21.11.2024 05:02:13
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
CVE-2020-25638
- EPSS 0.51%
- Published 02.12.2020 15:15:12
- Last modified 23.04.2025 20:15:19
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could...