Записи jetty
7 опубликованных записей вендора jetty.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 57,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2004-2478Эксплойта нет | Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Dca · unicenter web services distributed management | Высокая7,5 | — | 2,4 % | 31 дек. 2004 г. |
27Наблюдать | CVE-2006-6969Эксплойта нет | Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.utiljetty · jetty http server | Средняя6,8 | — | 1,6 % | 7 февр. 2007 г. |
24Наблюдать | CVE-2002-1533Proof of concept | Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP jetty · jetty | Средняя5,8 | — | 2,4 % | 31 мар. 2003 г. |
23Наблюдать | CVE-2002-1178Proof of concept | Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commandsjetty · jetty http server | Средняя5,0 | — | 9,5 % | 11 окт. 2002 г. |
21Наблюдать | CVE-2006-2758Proof of concept | Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ..jetty · jetty · CWE-22 | Средняя5,0 | — | 4,0 % | 1 июн. 2006 г. |
21Наблюдать | CVE-2004-2381Эксплойта нет | HttpRequest.java in Jetty HTTP Server before 4.2.19 allows remote attackers to cause denial of service (memory usage and application crash) jetty · jetty http server | Средняя5,0 | — | 1,8 % | 31 дек. 2004 г. |
20Наблюдать | CVE-2006-2759Эксплойта нет | jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary script source code via a capital P in the .jsp extension, and probablyjetty · jetty | Средняя5,0 | — | 1,4 % | 1 июн. 2006 г. |
- CVE-2004-247831Наблюдать
Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services D
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %ca · unicenter web services distributed management31 дек. 2004 г.
- CVE-2006-696927Наблюдать
Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util
СредняяCVSS 6,8Эксплойта нетEPSS 2 %jetty · jetty http server7 февр. 2007 г.
- CVE-2002-153324Наблюдать
Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP
СредняяCVSS 5,8Proof of conceptEPSS 2 %jetty · jetty31 мар. 2003 г.
- CVE-2002-117823Наблюдать
Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands
СредняяCVSS 5,0Proof of conceptEPSS 9 %jetty · jetty http server11 окт. 2002 г.
- CVE-2006-275821Наблюдать
Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ..
СредняяCVSS 5,0Proof of conceptEPSS 4 %jetty · jetty1 июн. 2006 г.
- CVE-2004-238121Наблюдать
HttpRequest.java in Jetty HTTP Server before 4.2.19 allows remote attackers to cause denial of service (memory usage and application crash)
СредняяCVSS 5,0Эксплойта нетEPSS 2 %jetty · jetty http server31 дек. 2004 г.
- CVE-2006-275920Наблюдать
jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary script source code via a capital P in the .jsp extension, and probably
СредняяCVSS 5,0Эксплойта нетEPSS 1 %jetty · jetty1 июн. 2006 г.