Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2011-4461

Disclosure Date: December 30, 2011 (last updated November 24, 2024)
Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
0
Attacker Value
Unknown

CVE-2006-6969

Disclosure Date: February 07, 2007 (last updated October 04, 2023)
Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remote attackers to guess a session identifier through brute force attacks, bypass authentication requirements, and possibly conduct cross-site request forgery attacks.
0
Attacker Value
Unknown

CVE-2005-3747

Disclosure Date: November 22, 2005 (last updated October 04, 2023)
Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters. NOTE: this might be the same issue as CVE-2006-2758.
0
Attacker Value
Unknown

CVE-2004-2381

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
HttpRequest.java in Jetty HTTP Server before 4.2.19 allows remote attackers to cause denial of service (memory usage and application crash) via HTTP requests with a large Content-Length.
0
Attacker Value
Unknown

CVE-2004-2478

Disclosure Date: December 31, 2004 (last updated October 04, 2023)
Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
0