CVE-2020-26217
- EPSS 93.01%
- Published 16.11.2020 21:15:12
- Last modified 23.05.2025 16:54:19
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone...
CVE-2020-11979
- EPSS 0.61%
- Published 01.10.2020 20:15:13
- Last modified 21.11.2024 04:59:02
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without ...
CVE-2020-1945
- EPSS 0.02%
- Published 14.05.2020 16:15:12
- Last modified 21.11.2024 05:11:42
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files fr...
CVE-2019-17571
- EPSS 53.46%
- Published 20.12.2019 17:15:11
- Last modified 21.11.2024 04:32:33
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic fo...
CVE-2019-12415
- EPSS 0.02%
- Published 23.10.2019 20:15:12
- Last modified 21.11.2024 04:22:47
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML E...
CVE-2019-10173
- EPSS 91.87%
- Published 23.07.2019 13:15:13
- Last modified 14.05.2025 20:02:54
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshall...
CVE-2013-7285
- EPSS 15.05%
- Published 15.05.2019 17:29:00
- Last modified 23.05.2025 16:54:47
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported for...
CVE-2019-0227
- EPSS 90.74%
- Published 01.05.2019 21:29:00
- Last modified 08.05.2025 18:13:51
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to buil...
CVE-2018-8032
- EPSS 2.34%
- Published 02.08.2018 13:29:00
- Last modified 08.05.2025 18:13:51
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
CVE-2015-9251
- EPSS 9.84%
- Published 18.01.2018 23:29:00
- Last modified 21.11.2024 02:40:09
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.