Vulnerability index

Browse CVEs

73 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Debian Linux HIGH 8.1
CVE-2020-35490EPSS 8%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc…

Fix: 2.9.10.8+
Fix from $1,950 2020-12-17
Debian Linux HIGH 8.1
CVE-2020-35491EPSS 9%

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc…

Fix: 2.9.10.8+
Fix from $1,950 2020-12-17
Debian Linux HIGH 8.1
CVE-2020-24750EPSS 7%

FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcompon…

Fix: 2.6.7.5 / 2.9.10.6+
Fix from $1,950 2020-09-17
Debian Linux HIGH 8.1
CVE-2020-11619

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.ao…

Fix: 2.9.10.4+
Fix from $1,950 2020-04-07
Debian Linux HIGH 8.1
CVE-2020-11620EPSS 6%

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jel…

Fix: 2.9.10.4+
Fix from $1,950 2020-04-07
Debian Linux HIGH 8.8
CVE-2020-11111

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* …

Fix: 2.9.10.4+
Fix from $1,950 2020-03-31
Debian Linux HIGH 8.8
CVE-2020-11112

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.pro…

Fix: 2.9.10.4+
Fix from $1,950 2020-03-31
Debian Linux HIGH 8.8
CVE-2020-11113EPSS 6%

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.…

Fix: 2.9.10.4+
Fix from $1,950 2020-03-31
Debian Linux HIGH 8.8
CVE-2020-10969

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPan…

Fix: 2.7.9.7 / 2.8.11.6+
Fix from $1,950 2020-03-26
Debian Linux HIGH 8.8
CVE-2020-10968

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.pro…

Fix: 2.9.10.4+
Fix from $1,950 2020-03-26
Debian Linux HIGH 8.8
CVE-2020-10672

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.trans…

Fix: 2.9.10.4+
Fix from $1,950 2020-03-18
Debian Linux HIGH 8.8
CVE-2020-10673EPSS 8%

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.type…

Fix: 2.6.7.4 / 2.9.10.4+
Fix from $1,950 2020-03-18
Debian Linux CRITICAL 9.8
CVE-2020-8840EPSS 27%

FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiC…

Fix: 2.7.9.7 / 2.8.11.5+
Fix from $2,300 2020-02-10
Debian Linux CRITICAL 9.8
CVE-2019-20330EPSS 9%

FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

Fix: 2.7.9.7 / 2.8.11.5+
Fix from $2,300 2020-01-03
Debian Linux MEDIUM 6.5
CVE-2019-14466

The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to per…

Patch available
Fix from $1,600 2019-12-31
Debian Linux HIGH 8.1
CVE-2019-17358

Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An auth…

Fix: after 1.2.7
Fix from $1,950 2019-12-12
Debian Linux CRITICAL 9.8
CVE-2019-17531EPSS 5%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for …

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2019-10-12
Debian Linux CRITICAL 9.8
CVE-2019-16942EPSS 6%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for …

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2019-10-01
Debian Linux CRITICAL 9.8
CVE-2019-16943

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for …

Fix: 2.6.7.3 / 2.8.11.5+
Fix from $2,300 2019-10-01
Debian Linux HIGH 7.5
CVE-2019-14439EPSS 11%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either global…

Fix: 2.6.7.3 / 2.7.9.6+
Fix from $1,950 2019-07-30
Debian Linux MEDIUM 5.9
CVE-2019-12384EPSS 45%

FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core clas…

Fix: 2.6.7.3 / 2.7.9.6+
Fix from $1,600 2019-06-24
Debian Linux MEDIUM 5.9
CVE-2019-12814EPSS 11%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a s…

Fix: 2.6.7.3 / 2.7.9.6+
Fix from $1,600 2019-06-19
Debian Linux HIGH 7.5
CVE-2019-12086EPSS 22%

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a sp…

Fix: 2.6.7.3 / 2.7.9.6+
Fix from $1,950 2019-05-17
Debian Linux HIGH 7.5
CVE-2018-12022EPSS 7%

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a…

Patch available
Fix from $1,950 2019-03-21
Debian Linux HIGH 7.5
CVE-2018-12023EPSS 9%

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a…

Patch available
Fix from $1,950 2019-03-21
Debian Linux CRITICAL 9.8
CVE-2018-14718EPSS 13%

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class…

Fix: 2.6.7.3 / 2.7.9.5+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-14719EPSS 10%

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt an…

Fix: 2.6.7.3 / 2.7.9.5+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-14720EPSS 8%

FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspeci…

Fix: 2.6.7.2 / 2.7.9.5+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-19360EPSS 11%

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms c…

Fix: 2.7.9.5 / 2.8.11.3+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-19361EPSS 11%

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from po…

Fix: 2.7.9.5 / 2.8.11.3+
Fix from $2,300 2019-01-02