CVEs (35)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectOpenldap+1 more7Debian Linux Enterprise LinuxFedora+4 moreJun 17, 2026 May 28, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulner...Show more |
1Redhat 6Jboss Brms Jboss Enterprise Application PlatformJboss Enterprise Web Server+3 moreNov 21, 2024 Jan 23, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterp...Show more |
7Apache AppleCanonical+4 more19Bookkeeper Cyrus SaslDebian Linux+16 moreJun 17, 2026 Dec 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in...Show more |
1Redhat 2Edeploy Jboss Enterprise Web ServerNov 21, 2024 Dec 15, 2019 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 eDeploy has tmp file race condition flaws |
1Redhat 2Edeploy Jboss Enterprise Web ServerNov 21, 2024 Dec 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eDeploy has RCE via cPickle deserialization of untrusted data |
1Redhat 2Jboss Community Application Server Jboss Enterprise Web ServerNov 21, 2024 Dec 6, 2019 N/A· v4 3.3 LOW· v3 1.9 LOW· v2 An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies |
1Redhat 2Edeploy Jboss Enterprise Web ServerNov 21, 2024 Nov 21, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data |
1Redhat 2Jboss Enterprise Web Server KeycloakNov 21, 2024 Nov 13, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 JBoss KeyCloak is vulnerable to soft token deletion via CSRF |
2Apache Redhat2Jboss Enterprise Web Server StrutsNov 21, 2024 Nov 1, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. |
13Canonical DebianF5+10 more82A220 Firmware A320 FirmwareA800 Firmware+79 moreJun 17, 2026 Feb 27, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte r...Show more |
4Apache CanonicalDebian+1 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 21, 2024 Aug 2, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5...Show more |
5Apache CanonicalDebian+2 more10Debian Linux Fusion MiddlewareHospitality Guest Access+7 moreNov 21, 2024 Feb 28, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of...Show more |
1Redhat 15Data Grid Jboss A MqJboss Bpm Suite+12 moreMay 13, 2026 Nov 9, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Ope...Show more |
3Apache DebianRedhat11Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreMay 13, 2026 Oct 24, 2017 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_t...Show more |
6Apache CanonicalDebian+3 more58Active Iq Unified Manager Agile PlmCommunications Instant Messaging Server+55 moreApr 21, 2026 Oct 4, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to fal...Show more |
1Redhat 2Amq Jboss Enterprise Web ServerMay 13, 2026 Sep 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Console: CORS headers set to allow all in Red Hat AMQ. |
1Redhat 3Amq Jboss A MqJboss Enterprise Web ServerMay 13, 2026 Sep 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ. |
3Apache NetappRedhat227 Mode Transition Tool Enterprise Linux DesktopEnterprise Linux Eus+19 moreApr 21, 2026 Sep 19, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a speci...Show more |
6Apache CanonicalDebian+3 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 13, 2026 Aug 11, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the...Show more |
6Apache CanonicalDebian+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreMay 13, 2026 Aug 10, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to thos...Show more |