Vulnerabilities
Last updated 3 hours ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Incomplete fix for Apache Log4j vulnerability | Critical 9.0 | 4 years ago | 6 hours ago |
|
|
Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout | Medium Risk 6.0 | 5 months ago | 22 days ago |
|
|
Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters | Medium Risk 6.0 | 5 months ago | 22 days ago |
|
|
Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization | Medium Risk 6.0 | 2 months ago | 22 days ago |
|
|
Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration | Medium Risk 6.0 | 5 months ago | 22 days ago |
|
|
Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters | Medium Risk 6.0 | 5 months ago | 22 days ago |
|
|
Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility | Medium Risk 6.0 | 5 months ago | 22 days ago |
|
|
Apache Log4j does not verify the TLS hostname in its Socket Appender | Medium Risk 6.0 | 9 months ago | 22 days ago |
|
|
Improper Input Validation and Injection in Apache Log4j2 | Medium Risk 6.6 | 4 years ago | 3 months ago |
|
|
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender | Low Risk 3.7 | 6 years ago | 3 months ago |
|
|
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender | Low Risk 3.7 | 6 years ago | 3 months ago |
|
|
Deserialization of Untrusted Data in Log4j | Critical 9.8 | 6 years ago | 3 months ago |
|
|
Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion | High Risk 8.6 | 4 years ago | 3 months ago |
|
|
SQL Injection in Log4j 1.2.x | Critical 9.8 | 4 years ago | 3 months ago |
|
|
Remote code injection in Log4j | Critical 10.0 | 4 years ago | 11 months ago |
|
|
Remote code injection in Log4j | Critical 10.0 | 4 years ago | 11 months ago |
|
|
Apache Log4j 1.x (EOL) allows Denial of Service (DoS) | High Risk 7.5 | 3 years ago | 1 year ago |
|
|
Apache Log4j 1.x (EOL) allows Denial of Service (DoS) | High Risk 7.5 | 3 years ago | 1 year ago |
|
|
Deserialization of Untrusted Data in Log4j 1.x | High Risk 8.8 | 4 years ago | 1 year ago |
|
|
Deserialization of Untrusted Data in Log4j | Critical 9.8 | 6 years ago | 2 years ago |
|
|
Deserialization of Untrusted Data in Log4j | Critical 9.8 | 6 years ago | 2 years ago |
|
|
Deserialization of Untrusted Data in Apache Log4j | Critical 9.8 | 4 years ago | 2 years ago |
|
|
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data | High Risk 7.5 | 4 years ago | 2 years ago |
Page 1