CVE-2026-105111
- EPSS 0.25%
- Veröffentlicht 06.10.2026 19:44:18
- Zuletzt bearbeitet 07.10.2026 13:35:14
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL. This only happens when you're using Class2HTML to generate webpages for possibly-attacker-controlled class files, where Clas...
CVE-2026-94114
- EPSS 0.28%
- Veröffentlicht 06.10.2026 19:42:30
- Zuletzt bearbeitet 08.10.2026 06:16:45
Symbolic name not mapping to correct class. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different clas...
CVE-2022-42920
- EPSS 2.84%
- Veröffentlicht 07.11.2022 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:25:35
Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in application...