Vulnerabilities
Last updated 2 hours ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Incomplete fix for Apache Log4j vulnerability | Critical 9.0 | 4 years ago | 5 hours ago |
|
|
Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration | Medium Risk 6.0 | 5 months ago | 22 days ago |
|
|
Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters | Medium Risk 6.0 | 5 months ago | 22 days ago |
|
|
Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility | Medium Risk 6.0 | 5 months ago | 22 days ago |
|
|
Apache Log4j does not verify the TLS hostname in its Socket Appender | Medium Risk 6.0 | 9 months ago | 22 days ago |
|
|
Improper Input Validation and Injection in Apache Log4j2 | Medium Risk 6.6 | 4 years ago | 3 months ago |
|
|
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender | Low Risk 3.7 | 6 years ago | 3 months ago |
|
|
Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion | High Risk 8.6 | 4 years ago | 3 months ago |
|
|
Remote code injection in Log4j | Critical 10.0 | 4 years ago | 11 months ago |
|
|
Apache Log4j 1.x (EOL) allows Denial of Service (DoS) | High Risk 7.5 | 3 years ago | 1 year ago |
|
|
Deserialization of Untrusted Data in Log4j | Critical 9.8 | 6 years ago | 2 years ago |
Page 1