CVE-2024-47554
- EPSS 0.21%
- Veröffentlicht 03.10.2024 12:15:02
- Zuletzt bearbeitet 10.07.2025 21:10:32
Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from...
CVE-2024-47561
- EPSS 1.59%
- Veröffentlicht 03.10.2024 11:15:13
- Zuletzt bearbeitet 10.07.2025 21:04:01
Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue.
CVE-2024-7254
- EPSS 0.08%
- Veröffentlicht 19.09.2024 01:15:10
- Zuletzt bearbeitet 26.09.2025 17:10:19
Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknown...
CVE-2024-8096
- EPSS 0.21%
- Veröffentlicht 11.09.2024 10:15:02
- Zuletzt bearbeitet 30.07.2025 19:42:16
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. ...
CVE-2024-8372
- EPSS 0.17%
- Veröffentlicht 09.09.2024 15:15:12
- Zuletzt bearbeitet 28.04.2025 14:15:20
Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This...
CVE-2024-8373
- EPSS 0.03%
- Veröffentlicht 09.09.2024 15:15:12
- Zuletzt bearbeitet 12.02.2025 20:15:05
Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attack...
CVE-2024-6119
- EPSS 4.4%
- Veröffentlicht 03.09.2024 16:15:07
- Zuletzt bearbeitet 03.06.2025 10:51:54
Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal term...
CVE-2024-38808
- EPSS 0.27%
- Veröffentlicht 20.08.2024 08:15:05
- Zuletzt bearbeitet 18.06.2025 12:10:28
In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an ap...
CVE-2024-21147
- EPSS 0.53%
- Veröffentlicht 16.07.2024 23:15:16
- Zuletzt bearbeitet 17.06.2025 19:57:24
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0...
CVE-2024-21140
- EPSS 0.42%
- Veröffentlicht 16.07.2024 23:15:15
- Zuletzt bearbeitet 18.06.2025 12:09:38
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0...