Search CVE reports


Toggle filters

421 – 430 of 825 results


CVE-2014-0113

Medium priority
Ignored

CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute...

1 affected package

libstruts1.2-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libstruts1.2-java — — — — Not in release
Show less packages

CVE-2014-0112

Medium priority
Ignored

ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE:...

1 affected package

libstruts1.2-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libstruts1.2-java — — — — Not in release
Show less packages

CVE-2014-0054

Medium priority
Ignored

The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of...

1 affected package

libspring-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java — — — — —
Show less packages

CVE-2014-0107

Medium priority

Some fixes available 3 of 4

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load...

1 affected package

libxalan2-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libxalan2-java — — — — —
Show less packages

CVE-2014-1904

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the...

1 affected package

libspring-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java — — — — Not affected
Show less packages

CVE-2014-0094

Medium priority
Not affected

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.

1 affected package

libstruts1.2-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libstruts1.2-java — — — — —
Show less packages

CVE-2014-0050

Medium priority

Some fixes available 2 of 8

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a...

3 affected packages

libcommons-fileupload-java, tomcat6, tomcat7

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcommons-fileupload-java — — — — Not affected
tomcat6 — — — — Not in release
tomcat7 — — — — Not affected
Show less packages

CVE-2013-6235

Medium priority
Ignored

Multiple cross-site scripting (XSS) vulnerabilities in JAMon (Java Application Monitor) 2.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listenertype or (2) currentlistener parameter to...

1 affected package

libjamon-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libjamon-java — — — — —
Show less packages

CVE-2013-6429

Medium priority
Ignored

The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of...

1 affected package

libspring-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java — — — — Not affected
Show less packages

CVE-2013-7315

Medium priority
Ignored

The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a...

1 affected package

libspring-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java — — — — Not affected
Show less packages