Apache / Derby
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-46337 | Apache Derby: LDAP injection vulnerability in authenticator | CRITICAL | 9.8 | Nov 20, 2023 |
| CVE-2018-1313 | derby: Externally-controlled input vulnerability allows remote attacker to boot a database under attacker's control | MEDIUM | 5.3 | May 7, 2018 |
| CVE-2010-2232 | derby: SYSCS_EXPORT_TABLE can be used to overwrite derby files | HIGH | 7.5 | Oct 23, 2017 |
| CVE-2015-1832 | Derby: XXE attack possible by using XmlVTI and the XML datatype | CRITICAL | 9.1 | Oct 3, 2016 |
| CVE-2009-4269 | The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 performs a transformation that reduces the… | LOW | 2.1 | Aug 16, 2010 |
| CVE-2006-7217 | Apache Derby before 10.2.1.6 does not determine schema privilege requirements during the DropSchemaNode bind phase, which allows remote authenticated users to… | MEDIUM | 4.0 | Jul 5, 2007 |
| CVE-2006-7216 | Apache Derby before 10.2.1.6 does not determine privilege requirements for lock table statements at compilation time, and consequently does not enforce privile… | MEDIUM | 4.0 | Jul 5, 2007 |
| CVE-2005-4849 | Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the outpu… | MEDIUM | 5.0 | Jul 5, 2007 |
Showing 1 to 8 of 8 CVEs