Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 141

Количество 141

nvd логотип

CVE-2017-5645

больше 9 лет назад

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

CVSS3: 9.8
EPSS: Высокий
debian логотип

CVE-2017-5645

больше 9 лет назад

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or ...

CVSS3: 9.8
EPSS: Высокий
fstec логотип

BDU:2020-03624

больше 6 лет назад

Уязвимость реализации класса SmtpAppender библиотеки журналирования Java-программ Log4j, позволяющая нарушителю реализовать атаку типа «человек посередине»

CVSS3: 3.7
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:4118-1

больше 4 лет назад

Security update for log4j

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:1605-1

больше 4 лет назад

Security update for log4j

EPSS: Критический
github логотип

GHSA-p6xc-xr62-6r2g

больше 4 лет назад

Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion

CVSS3: 8.6
EPSS: Критический
ubuntu логотип

CVE-2021-45105

больше 4 лет назад

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

CVSS3: 5.9
EPSS: Критический
redhat логотип

CVE-2021-45105

больше 4 лет назад

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

CVSS3: 5.9
EPSS: Критический
nvd логотип

CVE-2021-45105

больше 4 лет назад

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

CVSS3: 5.9
EPSS: Критический
debian логотип

CVE-2021-45105

больше 4 лет назад

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and ...

CVSS3: 5.9
EPSS: Критический
fstec логотип

BDU:2021-05969

больше 4 лет назад

Уязвимость компонента JNDI библиотеки журналирования Java-программ Apache Log4j2, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:4109-1

больше 4 лет назад

Security update for logback

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:3999-1

больше 4 лет назад

Security update for log4j

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:1613-1

больше 4 лет назад

Security update for logback

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:1586-1

больше 4 лет назад

Security update for log4j

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:1577-1

больше 4 лет назад

Security update for log4j

EPSS: Критический
github логотип

GHSA-jfh8-c2jp-5v3q

больше 4 лет назад

Remote code injection in Log4j

CVSS3: 10
EPSS: Критический
ubuntu логотип

CVE-2021-44228

больше 4 лет назад

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS3: 10
EPSS: Критический
redhat логотип

CVE-2021-44228

больше 4 лет назад

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS3: 9.8
EPSS: Критический
nvd логотип

CVE-2021-44228

больше 4 лет назад

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS3: 10
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-5645

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

CVSS3: 9.8
89%
Высокий
больше 9 лет назад
debian логотип
CVE-2017-5645

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or ...

CVSS3: 9.8
89%
Высокий
больше 9 лет назад
fstec логотип
BDU:2020-03624

Уязвимость реализации класса SmtpAppender библиотеки журналирования Java-программ Log4j, позволяющая нарушителю реализовать атаку типа «человек посередине»

CVSS3: 3.7
8%
Низкий
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2021:4118-1

Security update for log4j

100%
Критический
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1605-1

Security update for log4j

100%
Критический
больше 4 лет назад
github логотип
GHSA-p6xc-xr62-6r2g

Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion

CVSS3: 8.6
100%
Критический
больше 4 лет назад
ubuntu логотип
CVE-2021-45105

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

CVSS3: 5.9
100%
Критический
больше 4 лет назад
redhat логотип
CVE-2021-45105

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

CVSS3: 5.9
100%
Критический
больше 4 лет назад
nvd логотип
CVE-2021-45105

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

CVSS3: 5.9
100%
Критический
больше 4 лет назад
debian логотип
CVE-2021-45105

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and ...

CVSS3: 5.9
100%
Критический
больше 4 лет назад
fstec логотип
BDU:2021-05969

Уязвимость компонента JNDI библиотеки журналирования Java-программ Apache Log4j2, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
100%
Критический
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:4109-1

Security update for logback

100%
Критический
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:3999-1

Security update for log4j

100%
Критический
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1613-1

Security update for logback

100%
Критический
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1586-1

Security update for log4j

100%
Критический
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1577-1

Security update for log4j

100%
Критический
больше 4 лет назад
github логотип
GHSA-jfh8-c2jp-5v3q

Remote code injection in Log4j

CVSS3: 10
100%
Критический
больше 4 лет назад
ubuntu логотип
CVE-2021-44228

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS3: 10
100%
Критический
больше 4 лет назад
redhat логотип
CVE-2021-44228

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS3: 9.8
100%
Критический
больше 4 лет назад
nvd логотип
CVE-2021-44228

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVSS3: 10
100%
Критический
больше 4 лет назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.