CVE-2021-35515
- EPSS 11.57%
- Veröffentlicht 13.07.2021 08:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:25
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
CVE-2020-17521
- EPSS 1.05%
- Veröffentlicht 07.12.2020 20:15:12
- Zuletzt bearbeitet 25.08.2026 16:28:27
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operatin...
CVE-2020-1945
- EPSS 1.81%
- Veröffentlicht 14.05.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:42
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files fr...
CVE-2020-10683
- EPSS 7.27%
- Veröffentlicht 01.05.2020 19:15:12
- Zuletzt bearbeitet 25.08.2026 16:28:27
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any a...
CVE-2020-1950
- EPSS 3%
- Veröffentlicht 23.03.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:43
A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
CVE-2020-1951
- EPSS 2.91%
- Veröffentlicht 23.03.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:43
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
CVE-2019-10219
- EPSS 2.17%
- Veröffentlicht 08.11.2019 15:15:11
- Zuletzt bearbeitet 25.08.2026 16:28:27
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
CVE-2019-2904
- EPSS 14.26%
- Veröffentlicht 16.10.2019 18:15:27
- Zuletzt bearbeitet 21.11.2024 04:41:46
Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacke...
CVE-2019-17359
- EPSS 8.95%
- Veröffentlicht 08.10.2019 14:15:10
- Zuletzt bearbeitet 12.05.2025 17:37:16
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
CVE-2019-2706
- EPSS 2.1%
- Veröffentlicht 23.04.2019 19:32:56
- Zuletzt bearbeitet 21.11.2024 04:41:24
Vulnerability in the Oracle Business Process Management Suite component of Oracle Fusion Middleware (subcomponent: BPM Foundation Services). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated...