CVE-2017-7525
- EPSS 77.34%
- Published 06.02.2018 15:29:00
- Last modified 21.11.2024 03:32:04
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the Obj...
CVE-2017-15095
- EPSS 7.41%
- Published 06.02.2018 15:29:00
- Last modified 21.11.2024 03:14:03
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMappe...
CVE-2018-5968
- EPSS 2.12%
- Published 22.01.2018 04:29:00
- Last modified 21.11.2024 04:09:46
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets ...
CVE-2018-2638
- EPSS 0.75%
- Published 18.01.2018 02:29:20
- Last modified 21.11.2024 04:04:07
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multipl...
CVE-2018-2627
- EPSS 0.51%
- Published 18.01.2018 02:29:20
- Last modified 06.05.2025 15:15:55
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Installer). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure ...
CVE-2018-2581
- EPSS 0.49%
- Published 18.01.2018 02:29:18
- Last modified 21.11.2024 04:03:58
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u161, 8u152 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multip...
CVE-2017-17485
- EPSS 79.79%
- Published 10.01.2018 18:29:01
- Last modified 27.08.2025 21:15:33
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to t...
CVE-2017-10388
- EPSS 0.54%
- Published 19.10.2017 17:29:05
- Last modified 20.04.2025 01:37:25
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unau...
CVE-2017-10346
- EPSS 0.58%
- Published 19.10.2017 17:29:04
- Last modified 20.04.2025 01:37:25
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthen...
CVE-2017-10347
- EPSS 0.73%
- Published 19.10.2017 17:29:04
- Last modified 20.04.2025 01:37:25
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthentic...