VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 19 hours ago
Reset
More filters (3)
Columns
EPSS ≥ 0.5Published from 2014-01-01Published to 2014-12-31
Overview 11 matches, all in RASP scope, all EPSS ≥ 0.5 · 3 protected · 1 KEV · 8 public PoC · 1 CISA SSVC · 0 disputed
11matches, all in RASP scope, all EPSS ≥ 0.5 3protected27.3% 1KEV9.1% 8public PoC72.7% 1CISA SSVC9.1% 0disputed0.0%
Critical 0 0.0% High 4 36.4% Medium 7 63.6% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 3 27.3% Rule in development 0 0.0% Mitigation candidate 7 63.6% No exploit published 0 0.0% No fix identified 1 9.1% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 3 27.3% not blocked 8 72.7% not established 0 0.0% unrecorded 0 0.0%
split by peak 5 / month
Unknown: 0None: 0Low: 0Medium: 7High: 4Critical: 0 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 0No fix identified: 1No exploit published: 0Mitigation candidate: 7Rule in development: 0Protected by RASP: 3 unrecorded: 0not established: 0not blocked: 8blocked by ARMR today: 3 No public exploit: 0Forecast only: 3Proof of concept only: 0Working exploit published: 7Exploited in the wild: 1 January 2014: 4 CVEs February 2014: 0 CVEs March 2014: 1 CVE April 2014: 5 CVEs May 2014: 0 CVEs June 2014: 0 CVEs July 2014: 1 CVE
Jan 14Feb 14Mar 14Apr 14May 14Jun 14Jul 14
11 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2014-3120 High 2014-07-28 Mitigation candidate Exploited in the wild The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.
CVE-2014-0114 High 2014-04-30 Protected by RASP Working exploit published Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.
CVE-2014-0113 High 2014-04-29 Mitigation candidate Working exploit published CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.
CVE-2014-0054 Medium 2014-04-17 Protected by RASP Forecast only The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
CVE-2013-5704 Medium 2014-04-15 No fix identified Forecast only The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
CVE-2014-0050 High 2014-04-01 Mitigation candidate Working exploit published MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
CVE-2014-0094 Medium 2014-03-11 Mitigation candidate Working exploit published The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.
CVE-2013-6429 Medium 2014-01-26 Protected by RASP Forecast only The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
CVE-2013-5880 Medium 2014-01-15 Mitigation candidate Working exploit published Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.0, 12.2.1, and 12.2.2 allows remote attackers to affect confidentiality via unknown vectors related to DM Others.
CVE-2013-5877 Medium 2014-01-15 Mitigation candidate Working exploit published Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.0, and 12.2.1 allows remote attackers to affect confidentiality via unknown vectors related to DM Others.
CVE-2013-5795 Medium 2014-01-15 Mitigation candidate Working exploit published Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.1, 12.2.2, and 12.2.3 allows remote attackers to affect confidentiality via unknown vectors related to DM Others.