CVE-2019-17359
- EPSS 7.63%
- Veröffentlicht 08.10.2019 14:15:10
- Zuletzt bearbeitet 12.05.2025 17:37:16
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
CVE-2019-12402
- EPSS 0.38%
- Veröffentlicht 30.08.2019 09:15:17
- Zuletzt bearbeitet 21.11.2024 04:22:45
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names insi...
CVE-2019-10086
- EPSS 0.26%
- Veröffentlicht 20.08.2019 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:22
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by defa...
CVE-2019-13990
- EPSS 10.42%
- Veröffentlicht 26.07.2019 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:25:50
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
CVE-2019-0188
- EPSS 2.24%
- Veröffentlicht 28.05.2019 19:29:02
- Zuletzt bearbeitet 21.11.2024 04:16:26
Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
CVE-2019-0227
- EPSS 90.74%
- Veröffentlicht 01.05.2019 21:29:00
- Zuletzt bearbeitet 08.05.2025 18:13:51
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to buil...
CVE-2019-5427
- EPSS 6.91%
- Veröffentlicht 22.04.2019 21:29:00
- Zuletzt bearbeitet 05.09.2025 17:23:58
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
CVE-2019-10247
- EPSS 6.59%
- Veröffentlicht 22.04.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:18:44
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 4...
CVE-2019-10246
- EPSS 1.7%
- Veröffentlicht 22.04.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:18:44
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory co...
CVE-2019-3773
- EPSS 0.34%
- Veröffentlicht 18.01.2019 22:29:01
- Zuletzt bearbeitet 21.11.2024 04:42:30
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.