Записи restlet
5 опубликованных записей вендора restlet.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-16 Configuration1
- CWE-502 Deserialization of Untrusted Data1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2013-4221Эксплойта нет | The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources using the Jarestlet · restlet · CWE-16 | Высокая7,5 | — | 2,9 % | 9 окт. 2013 г. |
31Наблюдать | CVE-2013-4271Эксплойта нет | The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allowrestlet · restlet · CWE-502 | Высокая7,5 | — | 2,9 % | 9 окт. 2013 г. |
31Наблюдать | CVE-2017-14868Эксплойта нет | Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a RESTrestlet · restlet · CWE-611 | Высокая7,5 | — | 2,5 % | 30 нояб. 2017 г. |
31Наблюдать | CVE-2017-14949Эксплойта нет | Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE arestlet · restlet · CWE-611 | Высокая7,5 | — | 2,4 % | 30 нояб. 2017 г. |
20Наблюдать | CVE-2014-1868Эксплойта нет | Restlet Framework 2.1.x before 2.1.7 and 2.x.x before 2.2 RC1, when using XMLRepresentation or XML serializers, allows attackers to cause a restlet · restlet framework | Средняя5,0 | — | 1,3 % | 6 окт. 2014 г. |
- CVE-2013-422131Наблюдать
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources using the Ja
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %restlet · restlet9 окт. 2013 г.
- CVE-2013-427131Наблюдать
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allow
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %restlet · restlet9 окт. 2013 г.
- CVE-2017-1486831Наблюдать
Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %restlet · restlet30 нояб. 2017 г.
- CVE-2017-1494931Наблюдать
Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE a
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %restlet · restlet30 нояб. 2017 г.
- CVE-2014-186820Наблюдать
Restlet Framework 2.1.x before 2.1.7 and 2.x.x before 2.2 RC1, when using XMLRepresentation or XML serializers, allows attackers to cause a
СредняяCVSS 5,0Эксплойта нетEPSS 1 %restlet · restlet framework6 окт. 2014 г.