Show filters
25 Total Results
Displaying 21-25 of 25
Sort by:
Attacker Value
Unknown

CVE-2018-1339

Disclosure Date: April 25, 2018 (last updated November 08, 2023)
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.
0
Attacker Value
Unknown

CVE-2017-18239

Disclosure Date: March 18, 2018 (last updated November 26, 2024)
A time-sensitive equality check on the JWT signature in the JsonWebToken.validate method in main/scala/authentikat/jwt/JsonWebToken.scala in authentikat-jwt (aka com.jason-goodwin/authentikat-jwt) version 0.4.5 and earlier allows the supplier of a JWT token to guess bit after bit of the signature by repeating validation requests.
0
Attacker Value
Unknown

CVE-2016-4434

Disclosure Date: September 30, 2017 (last updated November 08, 2023)
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.
0
Attacker Value
Unknown

CVE-2016-6809

Disclosure Date: April 06, 2017 (last updated November 08, 2023)
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
Attacker Value
Unknown

CVE-2015-3271

Disclosure Date: December 15, 2016 (last updated November 25, 2024)
Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.
0