Apache

Log4net

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 06.10.2026 19:52:31
  • Zuletzt bearbeitet 07.10.2026 15:17:07

Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net. Every character outside visible ASCII and space was removed from the record instead of being escaped, so non-ASCII text and control characters such ...

  • EPSS 0.33%
  • Veröffentlicht 06.10.2026 19:51:25
  • Zuletzt bearbeitet 07.10.2026 15:17:07

Insufficient Logging vulnerability in the EventLogAppender of Apache log4net. Long messages were truncated to a fixed size that exceeds what the Windows Event Log accepts once the log and source names are counted, and the event log then stored nothi...

  • EPSS 0.34%
  • Veröffentlicht 06.10.2026 19:50:19
  • Zuletzt bearbeitet 07.10.2026 15:17:06

Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net. Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw a...

  • EPSS 0.34%
  • Veröffentlicht 06.10.2026 19:49:03
  • Zuletzt bearbeitet 07.10.2026 15:17:06

Improper Handling of Unicode Encoding vulnerability in the SmtpPickupDirAppender of Apache log4net. Content that the mail file writer cannot encode, such as an unpaired UTF-16 surrogate, made the write throw. Every buffered event in the batch was di...

  • EPSS 0.33%
  • Veröffentlicht 06.10.2026 19:47:44
  • Zuletzt bearbeitet 07.10.2026 17:16:46

Improper Neutralization of Null Byte or NUL Character vulnerability in the OutputDebugStringAppender of Apache log4net. A NUL character in logged content ended the debug output record at that point, so everything the layout rendered after it, includ...

  • EPSS 0.34%
  • Veröffentlicht 06.10.2026 19:46:33
  • Zuletzt bearbeitet 07.10.2026 13:35:14

Improper Neutralization of Null Byte or NUL Character vulnerability in the EventLogAppender of Apache log4net. A NUL character in logged content ended the Windows Event Log record at that point, so everything the layout rendered after it, including ...

  • EPSS 0.75%
  • Veröffentlicht 10.04.2026 15:44:17
  • Zuletzt bearbeitet 22.04.2026 14:13:45

Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list , in versions before 3.3.0, fail ...

  • EPSS 17.37%
  • Veröffentlicht 11.05.2020 17:15:10
  • Zuletzt bearbeitet 21.11.2024 03:59:32

Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.

  • EPSS 6.23%
  • Veröffentlicht 09.03.2006 20:02:00
  • Zuletzt bearbeitet 16.06.2026 22:21:11

Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.