CVE-2018-14720
- EPSS 2.52%
- Published 02.01.2019 18:29:00
- Last modified 21.11.2024 03:49:40
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
- EPSS 6.13%
- Published 02.01.2019 18:29:00
- Last modified 21.11.2024 03:49:40
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
CVE-2018-19360
- EPSS 3.08%
- Published 02.01.2019 18:29:00
- Last modified 21.11.2024 03:57:48
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.
CVE-2018-19361
- EPSS 2.44%
- Published 02.01.2019 18:29:00
- Last modified 21.11.2024 03:57:48
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
CVE-2018-19362
- EPSS 3.08%
- Published 02.01.2019 18:29:00
- Last modified 21.11.2024 03:57:48
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.
CVE-2019-3500
- EPSS 0.12%
- Published 02.01.2019 07:29:00
- Last modified 21.11.2024 04:42:08
aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file.
CVE-2018-20650
- EPSS 0.36%
- Published 01.01.2019 16:29:00
- Last modified 21.11.2024 04:01:56
A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in pdfdetach.
CVE-2018-20622
- EPSS 1.34%
- Published 31.12.2018 19:29:00
- Last modified 06.05.2025 17:15:49
JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.
CVE-2018-20584
- EPSS 0.44%
- Published 30.12.2018 05:29:01
- Last modified 21.11.2024 04:01:47
JasPer 2.0.14 allows remote attackers to cause a denial of service (application hang) via an attempted conversion to the jp2 format.
CVE-2018-20549
- EPSS 0.83%
- Published 28.12.2018 16:29:05
- Last modified 21.11.2024 04:01:42
There is an illegal WRITE memory access at caca/file.c (function caca_file_read) in libcaca 0.99.beta19.