Vulnerability index

Browse CVEs

73 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
HIGH 8.1 CVE-2020-35490EPSS 8% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc… Debian Linux 2.9.10.8+ Fix from $1,9502020-12-17 HIGH 8.1 CVE-2020-35491EPSS 9% FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc… Debian Linux 2.9.10.8+ Fix from $1,9502020-12-17 HIGH 8.1 CVE-2020-24750EPSS 7% FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcompon… Debian Linux 2.6.7.5 / 2.9.10.6+ Fix from $1,9502020-09-17 HIGH 8.1 CVE-2020-11619 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.ao… Debian Linux 2.9.10.4+ Fix from $1,9502020-04-07 HIGH 8.1 CVE-2020-11620EPSS 6% FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jel… Debian Linux 2.9.10.4+ Fix from $1,9502020-04-07 HIGH 8.8 CVE-2020-11111 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* … Debian Linux 2.9.10.4+ Fix from $1,9502020-03-31 HIGH 8.8 CVE-2020-11112 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.pro… Debian Linux 2.9.10.4+ Fix from $1,9502020-03-31 HIGH 8.8 CVE-2020-11113EPSS 6% FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.… Debian Linux 2.9.10.4+ Fix from $1,9502020-03-31 HIGH 8.8 CVE-2020-10969 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPan… Debian Linux 2.7.9.7 / 2.8.11.6+ Fix from $1,9502020-03-26 HIGH 8.8 CVE-2020-10968 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.pro… Debian Linux 2.9.10.4+ Fix from $1,9502020-03-26 HIGH 8.8 CVE-2020-10672 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.trans… Debian Linux 2.9.10.4+ Fix from $1,9502020-03-18 HIGH 8.8 CVE-2020-10673EPSS 8% FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.type… Debian Linux 2.6.7.4 / 2.9.10.4+ Fix from $1,9502020-03-18 CRITICAL 9.8 CVE-2020-8840EPSS 27% FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiC… Debian Linux 2.7.9.7 / 2.8.11.5+ Fix from $2,3002020-02-10 CRITICAL 9.8 CVE-2019-20330EPSS 9% FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking. Debian Linux 2.7.9.7 / 2.8.11.5+ Fix from $2,3002020-01-03 MEDIUM 6.5 CVE-2019-14466 The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to per… Debian Linux Patch available Fix from $1,6002019-12-31 HIGH 8.1 CVE-2019-17358 Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An auth… Debian Linux after 1.2.7 Fix from $1,9502019-12-12 CRITICAL 9.8 CVE-2019-17531EPSS 5% A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for … Debian Linux 2.6.7.3 / 2.8.11.5+ Fix from $2,3002019-10-12 CRITICAL 9.8 CVE-2019-16942EPSS 6% A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for … Debian Linux 2.6.7.3 / 2.8.11.5+ Fix from $2,3002019-10-01 CRITICAL 9.8 CVE-2019-16943 A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for … Debian Linux 2.6.7.3 / 2.8.11.5+ Fix from $2,3002019-10-01 HIGH 7.5 CVE-2019-14439EPSS 11% A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either global… Debian Linux 2.6.7.3 / 2.7.9.6+ Fix from $1,9502019-07-30 MEDIUM 5.9 CVE-2019-12384EPSS 45% FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core clas… Debian Linux 2.6.7.3 / 2.7.9.6+ Fix from $1,6002019-06-24 MEDIUM 5.9 CVE-2019-12814EPSS 11% A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a s… Debian Linux 2.6.7.3 / 2.7.9.6+ Fix from $1,6002019-06-19 HIGH 7.5 CVE-2019-12086EPSS 22% A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a sp… Debian Linux 2.6.7.3 / 2.7.9.6+ Fix from $1,9502019-05-17 HIGH 7.5 CVE-2018-12022EPSS 7% An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a… Debian Linux Patch available Fix from $1,9502019-03-21 HIGH 7.5 CVE-2018-12023EPSS 9% An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a… Debian Linux Patch available Fix from $1,9502019-03-21 CRITICAL 9.8 CVE-2018-14718EPSS 13% FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class… Debian Linux 2.6.7.3 / 2.7.9.5+ Fix from $2,3002019-01-02 CRITICAL 9.8 CVE-2018-14719EPSS 10% FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt an… Debian Linux 2.6.7.3 / 2.7.9.5+ Fix from $2,3002019-01-02 CRITICAL 9.8 CVE-2018-14720EPSS 8% FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspeci… Debian Linux 2.6.7.2 / 2.7.9.5+ Fix from $2,3002019-01-02 CRITICAL 9.8 CVE-2018-19360EPSS 11% FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms c… Debian Linux 2.7.9.5 / 2.8.11.3+ Fix from $2,3002019-01-02 CRITICAL 9.8 CVE-2018-19361EPSS 11% FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from po… Debian Linux 2.7.9.5 / 2.8.11.3+ Fix from $2,3002019-01-02