Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
caucho resin vulnerabilities and exploits
(subscribe to this query)
445
VMScore
CVE-2021-44138
There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote malicious users to read files in arbitrary directories via a ; in a pathname within an HTTP request.
Caucho Resin
445
VMScore
CVE-2014-2966
The ISO-8859-1 encoder in Resin Pro prior to 4.0.40 does not properly perform Unicode transformations, which allows remote malicious users to bypass intended text restrictions via crafted characters, as demonstrated by bypassing an XSS protection mechanism.
Caucho Resin 4.0.36
Caucho Resin 4.0.38
Caucho Resin
Caucho Resin 4.0.37
668
VMScore
CVE-2012-2965
Caucho Quercus, as distributed in Resin prior to 4.0.29, does not properly handle unspecified characters in the names of variables, which has unknown impact and remote attack vectors, related to an "HTTP Parameter Contamination" issue.
Caucho Resin 2.0.2
Caucho Resin 4.0.7
Caucho Resin 3.1.4
Caucho Resin 2.1.0
Caucho Resin 3.1.11
Caucho Resin 3.0.16
Caucho Resin 4.0.12
Caucho Resin 4.0.18
Caucho Resin 2.1.6
Caucho Resin 4.0.21
Caucho Resin 3.0.7
Caucho Resin 2.1.8
Caucho Resin 4.0.1
Caucho Resin 3.0.19
Caucho Resin 3.0.14
Caucho Resin 2.1.12
Caucho Resin 2.1.11
Caucho Resin 2.1.13
Caucho Resin 2.1.9
Caucho Resin 4.0.22
Caucho Resin 3.1.10
Caucho Resin 4.0.15
668
VMScore
CVE-2012-2966
Caucho Quercus, as distributed in Resin prior to 4.0.29, overwrites entries in the SERVER superglobal array on the basis of POST parameters, which has unspecified impact and remote attack vectors.
Caucho Resin 2.0.2
Caucho Resin 4.0.7
Caucho Resin 3.1.4
Caucho Resin 2.1.0
Caucho Resin 3.1.11
Caucho Resin 3.0.16
Caucho Resin 4.0.12
Caucho Resin 4.0.18
Caucho Resin 2.1.6
Caucho Resin 4.0.21
Caucho Resin 3.0.7
Caucho Resin 2.1.8
Caucho Resin 4.0.1
Caucho Resin 3.0.19
Caucho Resin 3.0.14
Caucho Resin 2.1.12
Caucho Resin 2.1.11
Caucho Resin 2.1.13
Caucho Resin 2.1.9
Caucho Resin 4.0.22
Caucho Resin 3.1.10
Caucho Resin 4.0.15
668
VMScore
CVE-2012-2967
Caucho Quercus, as distributed in Resin prior to 4.0.29, does not properly implement the == (equals sign equals sign) operator for comparisons, which has unspecified impact and context-dependent attack vectors.
Caucho Resin 2.0.2
Caucho Resin 4.0.7
Caucho Resin 3.1.4
Caucho Resin 2.1.0
Caucho Resin 3.1.11
Caucho Resin 3.0.16
Caucho Resin 4.0.12
Caucho Resin 4.0.18
Caucho Resin 2.1.6
Caucho Resin 4.0.21
Caucho Resin 3.0.7
Caucho Resin 2.1.8
Caucho Resin 4.0.1
Caucho Resin 3.0.19
Caucho Resin 3.0.14
Caucho Resin 2.1.12
Caucho Resin 2.1.11
Caucho Resin 2.1.13
Caucho Resin 2.1.9
Caucho Resin 4.0.22
Caucho Resin 3.1.10
Caucho Resin 4.0.15
445
VMScore
CVE-2012-2968
Directory traversal vulnerability in Caucho Quercus, as distributed in Resin prior to 4.0.29, allows remote malicious users to create files in arbitrary directories via a .. (dot dot) in a pathname within an HTTP request.
Caucho Resin 2.0.2
Caucho Resin 4.0.7
Caucho Resin 3.1.4
Caucho Resin 2.1.0
Caucho Resin 3.1.11
Caucho Resin 3.0.16
Caucho Resin 4.0.12
Caucho Resin 4.0.18
Caucho Resin 2.1.6
Caucho Resin 4.0.21
Caucho Resin 3.0.7
Caucho Resin 2.1.8
Caucho Resin 4.0.1
Caucho Resin 3.0.19
Caucho Resin 3.0.14
Caucho Resin 2.1.12
Caucho Resin 2.1.11
Caucho Resin 2.1.13
Caucho Resin 2.1.9
Caucho Resin 4.0.22
Caucho Resin 3.1.10
Caucho Resin 4.0.15
570
VMScore
CVE-2012-2969
Caucho Quercus, as distributed in Resin prior to 4.0.29, allows remote malicious users to bypass intended restrictions on filename extensions for created files via a %00 sequence in a pathname within an HTTP request.
Caucho Resin 2.0.2
Caucho Resin 4.0.7
Caucho Resin 3.1.4
Caucho Resin 2.1.0
Caucho Resin 3.1.11
Caucho Resin 3.0.16
Caucho Resin 4.0.12
Caucho Resin 4.0.18
Caucho Resin 2.1.6
Caucho Resin 4.0.21
Caucho Resin 3.0.7
Caucho Resin 2.1.8
Caucho Resin 4.0.1
Caucho Resin 3.0.19
Caucho Resin 3.0.14
Caucho Resin 2.1.12
Caucho Resin 2.1.11
Caucho Resin 2.1.13
Caucho Resin 2.1.9
Caucho Resin 4.0.22
Caucho Resin 3.1.10
Caucho Resin 4.0.15
383
VMScore
CVE-2010-2087
Oracle Mojarra 1.2_14 and 2.0.2, as used in IBM WebSphere Application Server, Caucho Resin, and other applications, does not properly handle an unencrypted view state, which allows remote malicious users to conduct cross-site scripting (XSS) attacks or execute arbitrary Expressio...
Oracle Mojarra 1.2 14
Oracle Mojarra 2.0.2
435
VMScore
CVE-2010-2032
Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remote malicious users to inject arbitrary web script or HTML via the (1) digest_realm or (2) digest_usern...
Caucho Resin 4.0.6
Caucho Resin 3.1.5
Caucho Resin 3.1.10
1 EDB exploit
383
VMScore
CVE-2008-2462
Cross-site scripting (XSS) vulnerability in the viewfile documentation command in Caucho Resin prior to 3.0.25, and 3.1.x prior to 3.1.4, allows remote malicious users to inject arbitrary web script or HTML via the file parameter.
Caucho Resin
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »