CVE-2017-10357
- EPSS 0.73%
- Published 19.10.2017 17:29:04
- Last modified 20.04.2025 01:37:25
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows un...
CVE-2017-10345
- EPSS 0.76%
- Published 19.10.2017 17:29:03
- Last modified 20.04.2025 01:37:25
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Difficult to e...
CVE-2017-10281
- EPSS 0.73%
- Published 19.10.2017 17:29:02
- Last modified 20.04.2025 01:37:25
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploit...
CVE-2017-10285
- EPSS 0.58%
- Published 19.10.2017 17:29:02
- Last modified 20.04.2025 01:37:25
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthentica...
CVE-2017-10295
- EPSS 0.35%
- Published 19.10.2017 17:29:02
- Last modified 20.04.2025 01:37:25
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Difficult to expl...
CVE-2017-10268
- EPSS 0.04%
- Published 19.10.2017 17:29:01
- Last modified 20.04.2025 01:37:25
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and earlier. Difficult to exploit vulnerability allows high pr...
CVE-2017-10274
- EPSS 0.62%
- Published 19.10.2017 17:29:01
- Last modified 20.04.2025 01:37:25
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Smart Card IO). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9. Difficult to exploit vulnerability allows unauthenticated attacker with network acces...
CVE-2015-5739
- EPSS 10.07%
- Published 18.10.2017 20:29:00
- Last modified 20.04.2025 01:37:25
The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct HTTP request smuggling attacks via a space instead of a hyphen, as demonstrated by "Content Length" ...
CVE-2015-5740
- EPSS 6.04%
- Published 18.10.2017 20:29:00
- Last modified 20.04.2025 01:37:25
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request with two Content-length headers.
CVE-2017-0903
- EPSS 4.9%
- Published 11.10.2017 18:29:00
- Last modified 20.04.2025 01:37:25
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalat...