Get Vulnerability Updates

Data for SBOM Document ID: 14fdf11a-8972-4210-a7da-3455e8ec4c03

Key Value
Timestamp 2023-09-06T09:17:14-04:00
Signature unsigned
Tool Vendor: anchore
Name: grype
Version: 0.66.0
Component bom-ref: af63bd4c8601b7f1
Type: file
Name: .
Total Components

977

0.00 / 10

Vulnerability Severity Distribution

Critical
High
Medium
Low
None
Unknown
27.4%40.8%26.6%5.2%
CVE-2022-22965CVE-2022-22965CVE-2015-1427CVE-2015-1427CVE-2015-1427CVE-2015-1427CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE-2021-28169CVE ID100%100%90%90%80%80%70%70%60%60%50%50%40%40%30%30%20%20%10%10%0%0%EPSS Score (%)Top 15 CVEs by EPSS Score
Download SVG
Download PNG
Download CSV
Total Vulnerabilities

2085

Critical

572

High

850

Medium

554

Low

109

None

0

GHSA-h822-r4r5-v8jg
Severity: Critical

Polymorphic Typing issue in FasterXML jackson-databind...

GHSA-qxxx-2pp7-5hmx
Severity: Critical

jackson-databind is vulnerable to a deserialization flaw...

CVE-2018-7489
Severity: Critical

FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unaut...

CVE-2019-10211
Severity: Critical

Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via b...

GHSA-cggj-fvv3-cqwv
Severity: Critical

FasterXML jackson-databind allows unauthenticated remote code execution ...

GHSA-cggj-fvv3-cqwv
Severity: Critical

FasterXML jackson-databind allows unauthenticated remote code execution ...

GHSA-85cw-hj65-qqv9
Severity: Critical

Polymorphic Typing issue in FasterXML jackson-databind...

GHSA-rfx6-vp9g-rh7v
Severity: Critical

jackson-databind vulnerable to remote code execution due to incorrect deserialization and blocklist ...

CVE-2018-1115
Severity: Critical

postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_l...

GHSA-fmmc-742q-jg75
Severity: Critical

Polymorphic typing issue...

CVE-2019-17571
Severity: Critical

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted dat...

GHSA-gjmw-vf9h-g25v
Severity: Critical

Polymorphic typing issue...

GHSA-fmmc-742q-jg75
Severity: Critical

Polymorphic typing issue...

CVE-2012-4449
Severity: Critical

Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a...

CVE-2019-17571
Severity: Critical

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted dat...

#
ID
Description
Severity
EPSS Score
EPSS Percentile

1
CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
critical
0.94464
0.99993
2
CVE-2018-1270
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
critical
0.89353
0.99511
3
CVE-2017-7525
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
critical
0.77336
0.98911
4
CVE-2017-7525
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
critical
0.77336
0.98911
5
CVE-2017-7525
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
critical
0.77336
0.98911
6
CVE-2017-7525
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
critical
0.77336
0.98911
7
CVE-2017-7525
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
critical
0.77336
0.98911
8
CVE-2017-7525
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
critical
0.77336
0.98911
9
CVE-2017-7525
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
critical
0.77336
0.98911
10
CVE-2017-7525
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
critical
0.77336
0.98911
#
Name
Version
License
Purl

1
../
 
unknown
pkg:golang/..
2
../conf
 
unknown
pkg:golang/../conf
3
../logutil
 
unknown
pkg:golang/../logutil
4
../pb
 
unknown
pkg:golang/../pb
5
../pf
 
unknown
pkg:golang/../pf
6
./conf
 
unknown
pkg:golang/./conf
7
./logutil
 
unknown
pkg:golang/./logutil
8
./pb
 
unknown
pkg:golang/./pb
9
./pf
 
unknown
pkg:golang/./pf
10
aerospike-client-bc
${aerospike-client.version}
unknown
pkg:maven/com.aerospike/aerospike-client-bc@${aerospike-client.version}