Show filters
774 Total Results
Displaying 191-200 of 774
Sort by:
Attacker Value
Unknown

CVE-2022-22950

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.
Attacker Value
Unknown

CVE-2020-36518

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
Attacker Value
Unknown

CVE-2022-23437

Disclosure Date: January 24, 2022 (last updated February 23, 2025)
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
Attacker Value
Unknown

CVE-2022-21911

Disclosure Date: January 11, 2022 (last updated November 28, 2024)
.NET Framework Denial of Service Vulnerability
0
Attacker Value
Unknown

CVE-2021-22060

Disclosure Date: January 10, 2022 (last updated October 07, 2023)
In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.
Attacker Value
Unknown

CVE-2021-44832

Disclosure Date: December 28, 2021 (last updated February 23, 2025)
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
Attacker Value
Unknown

CVE-2020-19316

Disclosure Date: December 20, 2021 (last updated February 23, 2025)
OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.
Attacker Value
Unknown

CVE-2021-45105

Disclosure Date: December 18, 2021 (last updated February 23, 2025)
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
Attacker Value
Unknown

CVE-2021-42550

Disclosure Date: December 16, 2021 (last updated February 23, 2025)
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
Attacker Value
Unknown

CVE-2021-43225

Disclosure Date: December 15, 2021 (last updated December 28, 2023)
Bot Framework SDK Remote Code Execution Vulnerability