Java Exploits

370 exploits tracked across all sources.

Sort: Activity Stars
CVE-2022-25845 GITHUB HIGH java
fastjson < 1.2.83 - Deserialization of Untrusted Data via autoType Bypass
The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).
by JAckLosingHeart
5 stars
CVSS 8.1
CVE-2023-23638 GITHUB MEDIUM java
Apache Dubbo 2.7.0-2.7.21, 3.0.0-3.0.13, 3.1.0-3.1.5 - Remote Code Execution via Generic Invoke Deserialization
A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.21 and prior versions; Apache Dubbo 3.0.x version 3.0.13 and prior versions; Apache Dubbo 3.1.x version 3.1.5 and prior versions.
by JAckLosingHeart
5 stars
CVSS 5.0
CVE-2022-42889 GITHUB CRITICAL java
Apache Commons Text 1.5-1.9 - Remote Code Execution via String Interpolation
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.
by JAckLosingHeart
5 stars
CVSS 9.8
CVE-2024-22234 GITHUB HIGH java
Spring Security <6.1.7 & <6.2.2 - Info Disclosure
In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it directly uses the AuthenticationTrustResolver.isFullyAuthenticated(Authentication) method. Specifically, an application is vulnerable if: * The application uses AuthenticationTrustResolver.isFullyAuthenticated(Authentication) directly and a null authentication parameter is passed to it resulting in an erroneous true return value. An application is not vulnerable if any of the following is true: * The application does not use AuthenticationTrustResolver.isFullyAuthenticated(Authentication) directly. * The application does not pass null to AuthenticationTrustResolver.isFullyAuthenticated * The application only uses isFullyAuthenticated via Method Security https://docs.spring.io/spring-security/reference/servlet/authorization/method-security.html  or HTTP Request Security https://docs.spring.io/spring-security/reference/servlet/authorization/authorize-http-requests.html
by shellfeel
5 stars
CVSS 7.4
CVE-2023-0669 EXPLOITDB HIGH java
Fortra GoAnywhere MFT Unsafe Deserialization RCE
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.
by Youssef Muhammad
CVSS 7.2
CVE-2020-6828 GITHUB HIGH java
Firefox ESR < 68.7.0 - Path Traversal and Arbitrary File Write via Malicious Android Intent
A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrite in the user's profile directory. One exploitation vector for this would be to supply a user.js file providing arbitrary malicious preference values. Control of arbitrary preferences can lead to sufficient compromise such that it is generally equivalent to arbitrary code execution.<br> *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.
by slient2009
CVSS 7.5
CVE-2017-13286 GITHUB HIGH java
Android 8.0-8.1 - Local Privilege Escalation via OutputConfiguration Serialization Mismatch
In writeToParcel and readFromParcel of OutputConfiguration.java, there is a permission bypass due to mismatched serialization. This could lead to a local escalation of privilege where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-69683251.
by slient2009
CVSS 7.8
CVE-2021-34371 EXPLOITDB CRITICAL java
Neo4j < 3.4.18 and 3.5.0 - Remote Code Execution via RMI Deserialization
Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., through setSessionVariable. An attacker can abuse this for remote code execution because there are dependencies with exploitable gadget chains.
by Christopher Ellis
CVSS 9.8
CVE-2021-26705 EXPLOITDB CRITICAL java
SquareBox CatDV < 9.2 - Unauthenticated Sensitive RMI Method Invocation
An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getConnections without authentication, the results of which can be used to generate valid authentication tokens. These tokens can then be used to invoke administrative tasks within the application, such as disclosing password hashes.
by Christopher Ellis
CVSS 9.1
EIP-2026-103818 EXPLOITDB java
Tibco ObfuscationEngine 5.11 - Fixed Key Password Decryption
by Tess Sluyter
CVE-2018-2628 EXPLOITDB CRITICAL java
Oracle WebLogic Server <12.2.1.3 - RCE
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
by allyshka
CVSS 9.8
CVE-2018-3245 EXPLOITDB CRITICAL java
Oracle WebLogic Server <12.2.1.3 - RCE
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
by allyshka
CVSS 9.8
CVE-2017-8046 EXPLOITDB CRITICAL java
Spring Data REST < 2.6.9 and Spring Boot < 1.5.9 - Remote Code Execution via Malicious PATCH Request
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.
by Antonio Francesco Sardella
CVSS 9.8
CVE-2017-0784 GITHUB HIGH java
Android <7.1.2 - Privilege Escalation
A elevation of privilege vulnerability in the Android system (nfc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37287958.
by heeeeen
5 stars
CVSS 8.8
CVE-2017-0645 GITHUB MEDIUM java
Android <7.1.2 - Privilege Escalation
An elevation of privilege vulnerability in Bluetooth could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it is a local bypass of user interaction requirements. Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35385327.
by heeeeen
5 stars
CVSS 5.5
CVE-2017-0601 GITHUB MEDIUM java
Android 7.0-7.1.2 - Elevation of Privilege via Bluetooth File Acceptance
An Elevation of Privilege vulnerability in Bluetooth could potentially enable a local malicious application to accept harmful files shared via bluetooth without user permission. This issue is rated as Moderate due to local bypass of user interaction requirements. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-35258579.
by heeeeen
5 stars
CVSS 5.5
CVE-2017-5586 EXPLOITDB CRITICAL java
OpenText Documentum D2 4.x - Remote Code Execution via Deserialization
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries.
by Andrey B. Panfilov
CVSS 9.8
EIP-2026-100045 EXPLOITDB java VERIFIED
Samsung Devices KNOX Extensions - OTP TrustZone Trustlet Stack Buffer Overflow
by Google Security Research
EIP-2026-100044 EXPLOITDB java VERIFIED
Samsung Devices KNOX Extensions - OTP Service Heap Overflow
by Google Security Research
EIP-2026-118129 EXPLOITDB java VERIFIED
WinPower 4.9.0.4 - Local Privilege Escalation
by Kacper Szurek
EIP-2026-102382 EXPLOITDB java
JBoss JMXInvokerServlet JMXInvoker 0.3 - Remote Command Execution
by ikki
CVE-2014-2227 EXPLOITDB java VERIFIED
Ubiquiti Networks UniFi Video <3.0.1 - CSRF
The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.
by Seth Art
CVE-2013-1727 EXPLOITDB java VERIFIED
Firefox < 24.0 - Same Origin Policy Bypass and Cross-Site Scripting via Symlink and file: URL
Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and consequently conduct cross-site scripting (XSS) attacks or obtain password or cookie information, by using a symlink in conjunction with a file: URL for a local file.
by Takeshi Terada
EIP-2026-104677 EXPLOITDB java
phpLDAPadmin 0.9.4b - Denial of Service
by Alguien
CVE-2011-2357 EXPLOITDB java VERIFIED
Android 2.3.4 and 3.1 - Cross-Application Scripting via Browser URL Loading
Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local applications to bypass the sandbox and execute arbitrary Javascript in arbitrary domains by (1) causing the MAX_TAB number of tabs to be opened, then loading a URI to the targeted domain into the current tab, or (2) making two startActivity function calls beginning with the targeted domain's URI followed by the malicious Javascript while the UI focus is still associated with the targeted domain.
by Roee Hay