dawetmaster
165 exploits
Active since Aug 2013
FasterXML jackson-databind <2.9.10 - Info Disclosure
CVSS 9.8
jackson-databind < 2.6.7.3 - Remote Code Execution via Polymorphic Deserialization
CVSS 9.8
FasterXML jackson-databind < 2.9.10 - Remote Code Execution via Xalan JNDI Gadget Deserialization
CVSS 9.8
FasterXML jackson-databind <2.9.10 - Info Disclosure
CVSS 9.8
jackson-databind 2.0.0-2.9.10 - Remote Code Execution via Polymorphic Typing
CVSS 9.8
jackson-databind 2.0.0-2.9.10 - Remote Code Execution via P6Spy Default Typing
CVSS 9.8
FasterXML jackson-databind < 2.9.10 - Deserialization of Untrusted Data via EhcacheJtaTransactionManagerLookup
CVSS 9.8
jackson-databind 2.0.0-2.9.10 - Remote Code Execution via Polymorphic Typing with Log4j JNDI
CVSS 9.8
Openfire < 4.4.2 - Path Traversal via PluginServlet.java
CVSS 5.3
Ignite Realtime Openfire < 4.4.2 - Server-Side Request Forgery via FaviconServlet
CVSS 9.8
Netapp Snapcenter < 2.7.9.7 - Insecure Deserialization
CVSS 9.8
FasterXML Jackson-Databind <2.9.10.4 - Code Injection
CVSS 8.8
jackson-databind 2.7.0-2.7.9.6 - Deserialization of Untrusted Data via javax.swing.JEditorPane
CVSS 8.8
FasterXML jackson-databind <2.9.10.4 - Code Injection
CVSS 8.8
FasterXML jackson-databind <2.9.10.4 - RCE
CVSS 8.8
FasterXML Jackson-Databind <2.9.10.4 - Code Injection
CVSS 8.8
jackson-databind 2.9.0-2.9.10.3 - Deserialization of Untrusted Data via spring-aop MethodLocatingFactoryBean
CVSS 8.1
jackson-databind 2.9.0-2.9.10.3 - Deserialization of Untrusted Data via commons-jelly Gadget
CVSS 8.1
Apache Velocity Tools < 3.1 - Cross-Site Scripting via URL vm File Parameter
CVSS 6.1
jackson-databind 2.9.0-2.9.10.4 - Deserialization of Untrusted Data via apache/drill JNDIConnectionPool
CVSS 8.1
jackson-databind 2.9.0-2.9.10.4 - Deserialization of Untrusted Data via Oracle AQjms Gadgets
CVSS 8.1
FasterXML jackson-databind 2.9.0-2.9.10.4 - Deserialization of Untrusted Data via xalan2 JNDIConnectionPool
CVSS 8.1
jackson-databind 2.9.0-2.9.10.4 - Deserialization of Untrusted Data via org.jsecurity.realm.jndi.JndiRealmFactory
CVSS 8.1
JUnit4 4.7-4.13 - Local Information Disclosure via TemporaryFolder Rule
CVSS 4.4
Resteasy 3.0.0-3.11.9 and 4.0.0-4.5.9 - HTTP Response Header Injection via Improper Input Validation
CVSS 7.5