CVE-2018-8026
- EPSS 4.34%
- Veröffentlicht 05.07.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:07
This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.xml, enumsConfig.xml referred from schema.xml, TIKA parsecontext config file). In addition, Xinclude ...
CVE-2017-7658
- EPSS 11.35%
- Veröffentlicht 26.06.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:23
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a...
CVE-2017-7657
- EPSS 7.64%
- Veröffentlicht 26.06.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:23
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow...
CVE-2018-12538
- EPSS 0.43%
- Veröffentlicht 22.06.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:23
In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatche...
CVE-2018-1258
- EPSS 0.16%
- Veröffentlicht 11.05.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:28
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted...
CVE-2018-2846
- EPSS 0.38%
- Veröffentlicht 19.04.2018 02:29:06
- Zuletzt bearbeitet 21.11.2024 04:04:36
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Performance Schema). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access vi...
CVE-2018-2839
- EPSS 0.38%
- Veröffentlicht 19.04.2018 02:29:05
- Zuletzt bearbeitet 21.11.2024 04:04:35
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple prot...
CVE-2018-2810
- EPSS 0.1%
- Veröffentlicht 19.04.2018 02:29:04
- Zuletzt bearbeitet 21.11.2024 04:04:30
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols...
CVE-2018-2812
- EPSS 0.4%
- Veröffentlicht 19.04.2018 02:29:04
- Zuletzt bearbeitet 21.11.2024 04:04:31
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multipl...
CVE-2018-2813
- EPSS 0.27%
- Veröffentlicht 19.04.2018 02:29:04
- Zuletzt bearbeitet 21.11.2024 04:04:31
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows low privileged attacker...