Products: 1
    Vulnerabilities: 11
    Known Exploited: 0
    0
    Critical Level Threats
    4
    High Level Threats
    7
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-44138

    There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.

    Last Modified: Nov 21, 2024
    Published: Apr 04, 2022

    CVE-2014-2966

    The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted characters, as demonstrated by bypassing an XSS protection mechanism.

    Last Modified: Apr 12, 2025
    Published: Jul 26, 2014

    CVE-2012-2965

    Caucho Quercus, as distributed in Resin before 4.0.29, does not properly handle unspecified characters in the names of variables, which has unknown impact and remote attack vectors, related to an "HTTP Parameter Contamination" issue.

    Last Modified: Apr 11, 2025
    Published: Aug 12, 2012

    CVE-2012-2969

    Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to bypass intended restrictions on filename extensions for created files via a %00 sequence in a pathname within an HTTP request.

    Last Modified: Apr 11, 2025
    Published: Aug 12, 2012

    CVE-2012-2966

    Caucho Quercus, as distributed in Resin before 4.0.29, overwrites entries in the SERVER superglobal array on the basis of POST parameters, which has unspecified impact and remote attack vectors.

    Last Modified: Apr 11, 2025
    Published: Aug 12, 2012
    Items Per Page