Oracle / Glassfish Server
40 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-3314 | Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A malicious user can cause an administrator user to supply dangerous con… | MEDIUM | 6.1 | Jun 25, 2021 |
| CVE-2018-3210 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Java Server Faces). The supported version that is affected is… | MEDIUM | 5.3 | Oct 17, 2018 |
| CVE-2018-3152 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration). The supported version that is affected is 3.… | HIGH | 7.5 | Oct 17, 2018 |
| CVE-2018-2911 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Java Server Faces). The supported version that is affected is… | HIGH | 8.3 | Oct 17, 2018 |
| CVE-2018-14324 | The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin for the admin account. This allows remo… | CRITICAL | 9.8 | Jul 16, 2018 |
| CVE-2017-10400 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration Graphical User Interface). The supported versi… | MEDIUM | 5.4 | Oct 19, 2017 |
| CVE-2017-10393 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 3.0.… | MEDIUM | 6.3 | Oct 19, 2017 |
| CVE-2017-10391 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration). Supported versions that are affected are 3.0… | HIGH | 7.3 | Oct 19, 2017 |
| CVE-2017-10385 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 3.0.… | MEDIUM | 6.3 | Oct 19, 2017 |
| CVE-2017-1000030 | Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Java Key Store Password Disclosure vulnerability, that makes it possible to prov… | CRITICAL | 9.8 | Jul 13, 2017 |
| CVE-2017-1000029 | Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include arbitrary… | HIGH | 7.5 | Jul 13, 2017 |
| CVE-2017-1000028 | Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploit… | HIGH | 7.5 | Jul 13, 2017 |
| CVE-2017-3626 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Java Server Faces). The supported version that is affected is… | LOW | 3.1 | Apr 24, 2017 |
| CVE-2017-3250 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Security). Supported versions that are affected are 2.1.1, 3.… | HIGH | 7.3 | Jan 27, 2017 |
| CVE-2017-3249 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Security). Supported versions that are affected are 2.1.1, 3.… | HIGH | 7.3 | Jan 27, 2017 |
| CVE-2017-3247 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Core). Supported versions that are affected are 2.1.1, 3.0.1… | MEDIUM | 4.3 | Jan 27, 2017 |
| CVE-2017-3239 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration). Supported versions that are affected are 3.0… | LOW | 3.3 | Jan 27, 2017 |
| CVE-2016-5528 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Security). Supported versions that are affected are 2.1.1, 3.… | CRITICAL | 9.0 | Jan 27, 2017 |
| CVE-2016-5519 | Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2 allows remote authenticated users to aff… | HIGH | 8.8 | Oct 25, 2016 |
| CVE-2016-5477 | Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1 and 3.0.1 allows remote attackers to affect confidentialit… | MEDIUM | 5.8 | Jul 21, 2016 |
| CVE-2016-3608 | Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1 allows remote attackers to affect confidentiality via vect… | MEDIUM | 5.8 | Jul 21, 2016 |
| CVE-2016-3607 | Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1 and 3.1.2 allows remote attackers to affect confidentialit… | CRITICAL | 9.8 | Jul 21, 2016 |
| CVE-2016-1950 | nss: Heap buffer overflow vulnerability in ASN1 certificate parsing (MFSA 2016-35) | HIGH | 8.8 | Mar 13, 2016 |
| CVE-2015-7182 | nss: ASN.1 decoder heap overflow when decoding constructed OCTET STRING that mixes indefinite and definite length encodings (MFSA 2015-133) | CRITICAL | 9.8 | Nov 5, 2015 |
| CVE-2015-3237 | curl: SMB send off unrelated memory contents | MEDIUM | 6.4 | Jun 22, 2015 |
Showing 1 to 25 of 40 CVEs