FasterXML
65 exploits
Active since Jan 2018
FasterXML jackson-databind <2.9.9 - Code Injection
CVSS 7.5
FasterXML jackson-databind <2.9.9.1 - Deserialization
CVSS 5.9
jackson-databind 2.0.0-2.9.9 - Unauthenticated Arbitrary File Read via JDOM Polymorphic Typing
CVSS 5.9
jackson-databind < 2.9.9.2 - Remote Code Execution via Default Typing with Ehcache
CVSS 9.8
FasterXML jackson-databind <2.9.9.2 - Info Disclosure
CVSS 7.5
FasterXML jackson-databind <2.9.10 - Info Disclosure
CVSS 9.8
FasterXML jackson-databind < 2.9.10 - Remote Code Execution via Xalan JNDI Gadget Deserialization
CVSS 9.8
FasterXML jackson-databind <2.9.10 - Info Disclosure
CVSS 9.8
FasterXML jackson-databind < 2.9.10 - Deserialization of Untrusted Data via EhcacheJtaTransactionManagerLookup
CVSS 9.8
jackson-databind 2.0.0-2.9.10 - Remote Code Execution via Polymorphic Typing with Log4j JNDI
CVSS 9.8
Netapp Snapcenter < 2.7.9.7 - Insecure Deserialization
CVSS 9.8
FasterXML Jackson-Databind <2.9.10.4 - Code Injection
CVSS 8.8
jackson-databind 2.7.0-2.7.9.6 - Deserialization of Untrusted Data via javax.swing.JEditorPane
CVSS 8.8
FasterXML jackson-databind <2.9.10.4 - Code Injection
CVSS 8.8
FasterXML jackson-databind <2.9.10.4 - RCE
CVSS 8.8
FasterXML Jackson-Databind <2.9.10.4 - Code Injection
CVSS 8.8
jackson-databind 2.9.0-2.9.10.3 - Deserialization of Untrusted Data via spring-aop MethodLocatingFactoryBean
CVSS 8.1
jackson-databind 2.9.0-2.9.10.3 - Deserialization of Untrusted Data via commons-jelly Gadget
CVSS 8.1
jackson-databind 2.9.0-2.9.10.4 - Deserialization of Untrusted Data via apache/drill JNDIConnectionPool
CVSS 8.1
jackson-databind 2.9.0-2.9.10.4 - Deserialization of Untrusted Data via Oracle AQjms Gadgets
CVSS 8.1
FasterXML jackson-databind 2.9.0-2.9.10.4 - Deserialization of Untrusted Data via xalan2 JNDIConnectionPool
CVSS 8.1
jackson-databind 2.9.0-2.9.10.4 - Deserialization of Untrusted Data via org.jsecurity.realm.jndi.JndiRealmFactory
CVSS 8.1
FasterXML jackson-databind <2.9.10.6 - RCE
CVSS 8.1
jackson-databind 2.0.0-2.9.10.5 - Deserialization of Untrusted Data via JndiConfiguration
CVSS 8.1
jackson-databind 2.0.0-2.9.10.7 - Deserialization of Untrusted Data
CVSS 8.1