CVE-2019-0205
- EPSS 9.16%
- Veröffentlicht 29.10.2019 19:15:15
- Zuletzt bearbeitet 21.11.2024 04:16:29
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it ...
CVE-2019-0210
- EPSS 6.85%
- Veröffentlicht 29.10.2019 19:15:15
- Zuletzt bearbeitet 21.11.2024 04:16:29
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
CVE-2019-14838
- EPSS 1.14%
- Veröffentlicht 14.10.2019 15:15:09
- Zuletzt bearbeitet 21.11.2024 04:27:28
A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server
CVE-2019-17531
- EPSS 5.37%
- Veröffentlicht 12.10.2019 21:15:08
- Zuletzt bearbeitet 08.10.2026 21:17:16
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-ext...
CVE-2019-17267
- EPSS 4.63%
- Veröffentlicht 07.10.2019 00:15:10
- Zuletzt bearbeitet 07.10.2026 19:17:13
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.
CVE-2019-10212
- EPSS 1.88%
- Veröffentlicht 02.10.2019 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:39
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
CVE-2019-16942
- EPSS 5.73%
- Veröffentlicht 01.10.2019 17:15:10
- Zuletzt bearbeitet 08.10.2026 21:17:16
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1....
CVE-2019-16943
- EPSS 4.9%
- Veröffentlicht 01.10.2019 17:15:10
- Zuletzt bearbeitet 07.10.2026 21:17:01
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) ja...
CVE-2019-10202
- EPSS 5.18%
- Veröffentlicht 01.10.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:38
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterX...
CVE-2019-16869
- EPSS 8.42%
- Veröffentlicht 26.09.2019 16:15:11
- Zuletzt bearbeitet 08.10.2026 22:16:50
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.