Skip to content
Noroxi

restlet records

5 published records for vendor restlet.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

  1. 17

Bar: total · dark part: CISA KEV.

All records

5 records
  • CVE-2013-4221
    31Monitor

    The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources using the Ja

    HighCVSS 7.5No exploitEPSS 3%

    restlet · restletOct 9, 2013

  • CVE-2013-4271
    31Monitor

    The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allow

    HighCVSS 7.5No exploitEPSS 3%

    restlet · restletOct 9, 2013

  • Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST

    HighCVSS 7.5No exploitEPSS 3%

    restlet · restletNov 30, 2017

  • Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE a

    HighCVSS 7.5No exploitEPSS 2%

    restlet · restletNov 30, 2017

  • CVE-2014-1868
    20Monitor

    Restlet Framework 2.1.x before 2.1.7 and 2.x.x before 2.2 RC1, when using XMLRepresentation or XML serializers, allows attackers to cause a

    MediumCVSS 5.0No exploitEPSS 1%

    restlet · restlet frameworkOct 6, 2014