CVE-2019-2769
- EPSS 0.65%
- Veröffentlicht 23.07.2019 23:15:40
- Zuletzt bearbeitet 21.11.2024 04:41:31
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows ...
CVE-2019-2762
- EPSS 0.77%
- Veröffentlicht 23.07.2019 23:15:39
- Zuletzt bearbeitet 21.11.2024 04:41:30
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows ...
CVE-2019-10136
- EPSS 0.1%
- Veröffentlicht 02.07.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:29
It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity witho...
CVE-2019-10137
- EPSS 7.15%
- Veröffentlicht 02.07.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:29
A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this flaw to test the existence of arbitrary files, if they have access to...
CVE-2019-2697
- EPSS 4.16%
- Veröffentlicht 23.04.2019 19:32:56
- Zuletzt bearbeitet 21.11.2024 04:41:23
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protoc...
CVE-2019-2698
- EPSS 7.17%
- Veröffentlicht 23.04.2019 19:32:56
- Zuletzt bearbeitet 21.11.2024 04:41:23
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protoc...
CVE-2019-2684
- EPSS 1.96%
- Veröffentlicht 23.04.2019 19:32:55
- Zuletzt bearbeitet 21.11.2024 04:41:21
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthen...
CVE-2019-2602
- EPSS 0.17%
- Veröffentlicht 23.04.2019 19:32:50
- Zuletzt bearbeitet 21.11.2024 04:41:11
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unau...
CVE-2019-0223
- EPSS 0.41%
- Veröffentlicht 23.04.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:16:31
While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer cert...
CVE-2019-10245
- EPSS 1.59%
- Veröffentlicht 19.04.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:18:43
In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load.