Apache / Geronimo
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2013-1777 | geronimo: Improper RMI classloader implementation in JMX remoting functionality leading to arbitrary code execution | HIGH | 10.0 | Jul 11, 2013 |
| CVE-2011-5034 | apache-geronimo: hash table collisions CPU usage DoS | MEDIUM | 5.3 | Dec 30, 2011 |
| CVE-2009-0039 | Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remo… | MEDIUM | 6.8 | Apr 17, 2009 |
| CVE-2009-0038 | Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote atta… | MEDIUM | 4.3 | Apr 17, 2009 |
| CVE-2008-5518 | Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote… | HIGH | 9.4 | Apr 17, 2009 |
| CVE-2008-0732 | The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspeci… | LOW | 2.1 | Feb 12, 2008 |
| CVE-2007-5797 | SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authenticatio… | HIGH | 7.5 | Nov 3, 2007 |
| CVE-2007-5085 | Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "access to G… | MEDIUM | 5.0 | Sep 26, 2007 |
| CVE-2007-4548 | The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to… | HIGH | 10.0 | Aug 27, 2007 |
| CVE-2006-0254 | tomcat examples XSS | MEDIUM | 4.3 | Jan 18, 2006 |
Showing 1 to 10 of 10 CVEs