mortbay kayıtları
mortbay üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %36,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-310 Cryptographic Issues1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2009-4611İstismar yok | Mort Bay Jetty 6.x through 6.1.22 and 7.0.0 writes backtrace data without sanitizing non-printable characters, which might allow remote attamortbay · jetty · CWE-20 | Yüksek7,5 | — | %3,2 | 13 Oca 2010 |
28İzleyin | CVE-2009-1523Kavram kanıtı | Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attmortbay · jetty · CWE-22 | Orta5,0 | — | %25,8 | 5 May 2009 |
24İzleyin | CVE-2009-5049İstismar yok | WebApp JSP Snoop page XSS in jetty though 6.1.21.mortbay · jetty · CWE-79 | Orta6,1 | — | %1,6 | 6 Kas 2019 |
24İzleyin | CVE-2009-5048İstismar yok | Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20.mortbay · jetty · CWE-79 | Orta6,1 | — | %1,6 | 6 Kas 2019 |
22İzleyin | CVE-2011-4461İstismar yok | Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably,oracle · sun storage common array manager · CWE-310 | Orta5,3 | — | %4,9 | 29 Ara 2011 |
21İzleyin | CVE-2005-3747Kavram kanıtı | Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for mortbay · jetty · CWE-200 | Orta5,0 | — | %4,4 | 22 Kas 2005 |
21İzleyin | CVE-2009-4609İstismar yok | The Dump Servlet in Mort Bay Jetty 6.x and 7.0.0 allows remote attackers to obtain sensitive information about internal variables and other mortbay · jetty · CWE-200 | Orta5,0 | — | %1,8 | 13 Oca 2010 |
18İzleyin | CVE-2009-4612Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackemortbay · jetty · CWE-79 | Orta4,3 | — | %3,3 | 13 Oca 2010 |
18İzleyin | CVE-2009-4610Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script ormortbay · jetty · CWE-79 | Orta4,3 | — | %3,0 | 13 Oca 2010 |
18İzleyin | CVE-2009-1524İstismar yok | Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web script or HTML via mortbay · jetty · CWE-79 | Orta4,3 | — | %2,6 | 5 May 2009 |
17İzleyin | CVE-2009-3579İstismar yok | Cross-site scripting (XSS) vulnerability in the CookieDump.java sample application in Mort Bay Jetty 6.1.19 and 6.1.20 allows remote attackemortbay · jetty · CWE-79 | Orta4,3 | — | %1,1 | 7 Eki 2009 |
- CVE-2009-461131İzleyin
Mort Bay Jetty 6.x through 6.1.22 and 7.0.0 writes backtrace data without sanitizing non-printable characters, which might allow remote atta
YüksekCVSS 7,5İstismar yokEPSS %3mortbay · jetty13 Oca 2010
- CVE-2009-152328İzleyin
Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote att
OrtaCVSS 5,0Kavram kanıtıEPSS %26mortbay · jetty5 May 2009
- CVE-2009-504924İzleyin
WebApp JSP Snoop page XSS in jetty though 6.1.21.
OrtaCVSS 6,1İstismar yokEPSS %2mortbay · jetty6 Kas 2019
- CVE-2009-504824İzleyin
Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20.
OrtaCVSS 6,1İstismar yokEPSS %2mortbay · jetty6 Kas 2019
- CVE-2011-446122İzleyin
Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably,
OrtaCVSS 5,3İstismar yokEPSS %5oracle · sun storage common array manager29 Ara 2011
- CVE-2005-374721İzleyin
Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for
OrtaCVSS 5,0Kavram kanıtıEPSS %4mortbay · jetty22 Kas 2005
- CVE-2009-460921İzleyin
The Dump Servlet in Mort Bay Jetty 6.x and 7.0.0 allows remote attackers to obtain sensitive information about internal variables and other
OrtaCVSS 5,0İstismar yokEPSS %2mortbay · jetty13 Oca 2010
- CVE-2009-461218İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attacke
OrtaCVSS 4,3Kavram kanıtıEPSS %3mortbay · jetty13 Oca 2010
- CVE-2009-461018İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or
OrtaCVSS 4,3Kavram kanıtıEPSS %3mortbay · jetty13 Oca 2010
- CVE-2009-152418İzleyin
Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web script or HTML via
OrtaCVSS 4,3İstismar yokEPSS %3mortbay · jetty5 May 2009
- CVE-2009-357917İzleyin
Cross-site scripting (XSS) vulnerability in the CookieDump.java sample application in Mort Bay Jetty 6.1.19 and 6.1.20 allows remote attacke
OrtaCVSS 4,3İstismar yokEPSS %1mortbay · jetty7 Eki 2009