CVE-2021-36374
- EPSS 2.64%
- Veröffentlicht 14.07.2021 07:15:08
- Zuletzt bearbeitet 25.08.2026 16:28:27
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. ...
CVE-2021-33037
- EPSS 75.35%
- Veröffentlicht 12.07.2021 15:15:08
- Zuletzt bearbeitet 25.08.2026 16:28:27
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specific...
CVE-2021-29425
- EPSS 10.23%
- Veröffentlicht 13.04.2021 07:15:12
- Zuletzt bearbeitet 25.08.2026 16:28:27
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but ...
- EPSS 9.49%
- Veröffentlicht 01.03.2021 12:15:14
- Zuletzt bearbeitet 25.08.2026 16:28:27
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnera...
CVE-2021-25122
- EPSS 18.11%
- Veröffentlicht 01.03.2021 12:15:13
- Zuletzt bearbeitet 25.08.2026 16:28:27
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and use...
CVE-2021-26271
- EPSS 1.96%
- Veröffentlicht 26.01.2021 21:15:12
- Zuletzt bearbeitet 25.08.2026 16:28:27
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
CVE-2021-26272
- EPSS 2.22%
- Veröffentlicht 26.01.2021 21:15:12
- Zuletzt bearbeitet 25.08.2026 16:28:27
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
CVE-2021-24122
- EPSS 22.85%
- Veröffentlicht 14.01.2021 15:15:13
- Zuletzt bearbeitet 25.08.2026 16:28:27
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. ...
CVE-2020-36183
- EPSS 4.89%
- Veröffentlicht 07.01.2021 00:15:15
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.
CVE-2020-36179
- EPSS 20.93%
- Veröffentlicht 07.01.2021 00:15:14
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.