Search CVE reports


Toggle filters

61 – 70 of 72 results


CVE-2018-19361

Medium priority

Some fixes available 15 of 17

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Fixed Fixed Fixed Not affected
Show less packages

CVE-2018-19360

Medium priority

Some fixes available 15 of 17

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Fixed Fixed Fixed Not affected
Show less packages

CVE-2018-14721

Medium priority

Some fixes available 1 of 3

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-14720

Medium priority

Some fixes available 1 of 3

FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-14719

Medium priority

Some fixes available 1 of 3

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-14718

Medium priority

Some fixes available 1 of 3

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-1000873

Low priority
Needs evaluation

Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim...

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2018-7489

High priority
Fixed

FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by...

1 affected package

jackson-databind

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected
Show less packages

CVE-2017-7525

Medium priority

Some fixes available 6 of 10

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the...

2 affected packages

jackson-databind, libjackson-json-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Not affected
libjackson-json-java Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2017-15095

Medium priority

Some fixes available 6 of 9

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue...

2 affected packages

jackson-databind, libjackson-json-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackson-databind Not affected Not affected Not affected Not affected
libjackson-json-java Not affected Not affected Needs evaluation Needs evaluation
Show less packages