CVE-2021-29425
- EPSS 0.61%
- Veröffentlicht 13.04.2021 07:15:12
- Zuletzt bearbeitet 21.11.2024 06:01:04
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but ...
CVE-2021-3450
- EPSS 0.5%
- Veröffentlicht 25.03.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:33
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly ...
CVE-2021-21347
- EPSS 2.89%
- Veröffentlicht 23.03.2021 00:15:13
- Zuletzt bearbeitet 23.05.2025 17:41:49
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processe...
CVE-2021-21350
- EPSS 8.24%
- Veröffentlicht 23.03.2021 00:15:13
- Zuletzt bearbeitet 23.05.2025 17:43:08
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is a...
CVE-2020-11987
- EPSS 1.36%
- Veröffentlicht 24.02.2021 18:15:11
- Zuletzt bearbeitet 03.11.2025 20:15:42
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arb...
CVE-2021-27568
- EPSS 0.65%
- Veröffentlicht 23.02.2021 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:58:12
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs us...
CVE-2020-28491
- EPSS 0.39%
- Veröffentlicht 18.02.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:22:53
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
CVE-2021-2108
- EPSS 26.77%
- Veröffentlicht 20.01.2021 15:15:52
- Zuletzt bearbeitet 21.11.2024 06:02:23
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). The supported version that is affected is 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access v...
CVE-2021-2109
- EPSS 93.25%
- Veröffentlicht 20.01.2021 15:15:52
- Zuletzt bearbeitet 21.11.2024 06:02:23
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high...
CVE-2021-2075
- EPSS 29.69%
- Veröffentlicht 20.01.2021 15:15:50
- Zuletzt bearbeitet 21.11.2024 06:02:19
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unau...