CVE-2021-39149
- EPSS 4.74%
- Veröffentlicht 23.08.2021 18:15:12
- Zuletzt bearbeitet 07.10.2026 20:17:07
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...
CVE-2021-39151
- EPSS 4.74%
- Veröffentlicht 23.08.2021 18:15:12
- Zuletzt bearbeitet 07.10.2026 21:17:04
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...
CVE-2021-39139
- EPSS 4.54%
- Veröffentlicht 23.08.2021 18:15:10
- Zuletzt bearbeitet 07.10.2026 21:17:03
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. A user ...
CVE-2021-37695
- EPSS 1.32%
- Veröffentlicht 13.08.2021 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:15:43
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed F...
CVE-2021-32808
- EPSS 1.19%
- Veröffentlicht 12.08.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:47
ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malform...
CVE-2021-32809
- EPSS 1.19%
- Veröffentlicht 12.08.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:47
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionali...
- EPSS 0.86%
- Veröffentlicht 21.07.2021 15:15:20
- Zuletzt bearbeitet 21.11.2024 06:02:56
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Tools and Frameworks). The supported version that is affected is 11.3.1.5. Easily exploitable vulnerability allows low priv...
CVE-2021-2345
- EPSS 0.65%
- Veröffentlicht 21.07.2021 15:15:19
- Zuletzt bearbeitet 21.11.2024 06:02:55
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Tools and Frameworks). The supported version that is affected is 11.3.1.5. Easily exploitable vulnerability allows low priv...
CVE-2021-2346
- EPSS 0.51%
- Veröffentlicht 21.07.2021 15:15:19
- Zuletzt bearbeitet 21.11.2024 06:02:55
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Tools and Frameworks). The supported version that is affected is 11.3.1.5. Easily exploitable vulnerability allows low priv...
CVE-2021-35515
- EPSS 11.57%
- Veröffentlicht 13.07.2021 08:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:25
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.