CVE-2022-1259
- EPSS 0.18%
- Veröffentlicht 31.08.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:40:21
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.
CVE-2022-1319
- EPSS 0.23%
- Veröffentlicht 31.08.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:40:28
A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400...
CVE-2022-36033
- EPSS 0.96%
- Veröffentlicht 29.08.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:12:13
jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clic...
CVE-2021-3859
- EPSS 0.9%
- Veröffentlicht 26.08.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:40
A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.
CVE-2022-35278
- EPSS 1.27%
- Veröffentlicht 23.08.2022 15:15:11
- Zuletzt bearbeitet 21.11.2024 07:11:01
In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.
CVE-2022-37434
- EPSS 92.68%
- Veröffentlicht 05.08.2022 07:15:07
- Zuletzt bearbeitet 30.05.2025 20:15:30
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib s...
CVE-2022-21569
- EPSS 0.18%
- Veröffentlicht 19.07.2022 22:15:13
- Zuletzt bearbeitet 21.11.2024 06:44:58
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple prot...
CVE-2022-21547
- EPSS 0.1%
- Veröffentlicht 19.07.2022 22:15:12
- Zuletzt bearbeitet 21.11.2024 06:44:55
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Federated). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple pro...
CVE-2022-21550
- EPSS 38.32%
- Veröffentlicht 19.07.2022 22:15:12
- Zuletzt bearbeitet 21.11.2024 06:44:56
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.36 and prior, 7.5.26 and prior, 7.6.22 and prior and and 8.0.29 and prior. Difficult to exploit vulnerability allow...
CVE-2022-21553
- EPSS 0.1%
- Veröffentlicht 19.07.2022 22:15:12
- Zuletzt bearbeitet 21.11.2024 06:44:56
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple pro...