restlet records
5 published records for vendor restlet.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-16 Configuration1
- CWE-502 Deserialization of Untrusted Data1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2013-4221No exploit | The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources using the Jarestlet · restlet · CWE-16 | High7.5 | — | 2.9% | Oct 9, 2013 |
31Monitor | CVE-2013-4271No exploit | The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allowrestlet · restlet · CWE-502 | High7.5 | — | 2.9% | Oct 9, 2013 |
31Monitor | CVE-2017-14868No exploit | Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a RESTrestlet · restlet · CWE-611 | High7.5 | — | 2.5% | Nov 30, 2017 |
31Monitor | CVE-2017-14949No exploit | Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE arestlet · restlet · CWE-611 | High7.5 | — | 2.4% | Nov 30, 2017 |
20Monitor | CVE-2014-1868No exploit | Restlet Framework 2.1.x before 2.1.7 and 2.x.x before 2.2 RC1, when using XMLRepresentation or XML serializers, allows attackers to cause a restlet · restlet framework | Medium5.0 | — | 1.3% | Oct 6, 2014 |
- CVE-2013-422131Monitor
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources using the Ja
HighCVSS 7.5No exploitEPSS 3%restlet · restletOct 9, 2013
- CVE-2013-427131Monitor
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allow
HighCVSS 7.5No exploitEPSS 3%restlet · restletOct 9, 2013
- CVE-2017-1486831Monitor
Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST
HighCVSS 7.5No exploitEPSS 3%restlet · restletNov 30, 2017
- CVE-2017-1494931Monitor
Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE a
HighCVSS 7.5No exploitEPSS 2%restlet · restletNov 30, 2017
- CVE-2014-186820Monitor
Restlet Framework 2.1.x before 2.1.7 and 2.x.x before 2.2 RC1, when using XMLRepresentation or XML serializers, allows attackers to cause a
MediumCVSS 5.0No exploitEPSS 1%restlet · restlet frameworkOct 6, 2014