CVE-2022-22963
- EPSS 94.46%
- Veröffentlicht 01.04.2022 23:15:13
- Zuletzt bearbeitet 13.03.2025 16:36:53
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access ...
CVE-2021-31812
- EPSS 0.04%
- Veröffentlicht 12.06.2021 10:15:07
- Zuletzt bearbeitet 21.11.2024 06:06:16
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
CVE-2021-31811
- EPSS 0.41%
- Veröffentlicht 12.06.2021 10:15:07
- Zuletzt bearbeitet 21.11.2024 06:06:16
In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
CVE-2021-29505
- EPSS 90.77%
- Veröffentlicht 28.05.2021 21:15:08
- Zuletzt bearbeitet 30.05.2025 00:15:20
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input str...
CVE-2021-21409
- EPSS 4.98%
- Veröffentlicht 30.03.2021 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:48:17
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerabi...
CVE-2021-27906
- EPSS 0.54%
- Veröffentlicht 19.03.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:58:45
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
CVE-2021-23337
- EPSS 0.86%
- Veröffentlicht 15.02.2021 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:51:31
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
CVE-2020-28500
- EPSS 0.2%
- Veröffentlicht 15.02.2021 11:15:12
- Zuletzt bearbeitet 21.11.2024 05:22:55
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
CVE-2021-21290
- EPSS 0.02%
- Veröffentlicht 08.02.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:56
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems inv...
CVE-2020-36183
- EPSS 2.72%
- Veröffentlicht 07.01.2021 00:15:15
- Zuletzt bearbeitet 21.11.2024 05:28:55
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.