CVE-2016-5710
- EPSS 0.14%
- Published 11.02.2020 12:15:11
- Last modified 21.11.2024 02:54:52
NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.
CVE-2019-10247
- EPSS 6.59%
- Published 22.04.2019 20:29:00
- Last modified 21.11.2024 04:18:44
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 4...
CVE-2019-10246
- EPSS 1.7%
- Published 22.04.2019 20:29:00
- Last modified 21.11.2024 04:18:44
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory co...
CVE-2018-18314
- EPSS 5.85%
- Published 07.12.2018 21:29:00
- Last modified 21.11.2024 03:55:41
Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
CVE-2018-18313
- EPSS 3.54%
- Published 07.12.2018 21:29:00
- Last modified 21.11.2024 03:55:41
Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory.
CVE-2018-18311
- EPSS 13.02%
- Published 07.12.2018 21:29:00
- Last modified 21.11.2024 03:55:40
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
CVE-2018-18312
- EPSS 9.27%
- Published 05.12.2018 22:29:00
- Last modified 21.11.2024 03:55:40
Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
CVE-2018-11784
- EPSS 82.62%
- Published 04.10.2018 13:29:00
- Last modified 21.11.2024 03:44:01
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause...
CVE-2018-1000632
- EPSS 1%
- Published 20.08.2018 19:31:31
- Last modified 21.11.2024 03:40:16
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be explo...
CVE-2017-7658
- EPSS 11.35%
- Published 26.06.2018 17:29:00
- Last modified 21.11.2024 03:32:23
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a...