themidnightcoders records
2 published records for vendor themidnightcoders.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-502 Deserialization of Untrusted Data1
- CWE-611 Improper Restriction of XML External Entity Reference1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2017-3207No exploit | WebORB for Java by Midnight Coders, version 5.1.1.0, Action Message Format (AMF3) Java implementation is vulnerable to insecure deserializationthemidnightcoders · weborb for java · CWE-502 | Critical9.8 | — | 8.2% | Jun 11, 2018 |
40Plan | CVE-2017-3208No exploit | The Java implementation of AMF3 deserializers used by WebORB for Java by Midnight Coders, version 5.1.1.0, allows external entity referencesthemidnightcoders · weborb for java · CWE-611 | Critical9.8 | — | 4.0% | Jun 11, 2018 |
- CVE-2017-320741Plan
WebORB for Java by Midnight Coders, version 5.1.1.0, Action Message Format (AMF3) Java implementation is vulnerable to insecure deserialization
CriticalCVSS 9.8No exploitEPSS 8%themidnightcoders · weborb for javaJun 11, 2018
- CVE-2017-320840Plan
The Java implementation of AMF3 deserializers used by WebORB for Java by Midnight Coders, version 5.1.1.0, allows external entity references
CriticalCVSS 9.8No exploitEPSS 4%themidnightcoders · weborb for javaJun 11, 2018