- Graphwise Platform Documentation
- Graph Modeling
- Graph Modeling Release Notes
- Graph Modeling and Semantic Analytics 10.3 Release Notes
- Graph Modeling & Semantic Analytics 10.3.1 Patch Release Notes
Graph Modeling and Semantic Analytics 10.3.1 delivers important stability and usability improvements, resolving critical project-linking issues, addressing ontology and archive import bugs, and improving overall search performance.
Internal ID | Details | Severity |
|---|---|---|
GWP-2745 | Project linking drag and drop now works as intended when creating links to a concept. | Critical |
GWP-2787 | Quick search now returns hidden-label results in non-default display languages. | Major |
GWP-2531 | Responsiveness when searching linked concepts across projects has been improved. | Major |
GWP-1970 | ADF no longer becomes unavailable because of the dependent-service readiness checks. | Major |
GWP-2925 | Performance when retrieving concept sub-trees has been improved. | Major |
GWP-2455 | Ontology's Definition and Description fields now show the correct input. | Major |
GWP-2235 | Project creation no longer generates URI templates from unsupported title characters. | Major |
GWP-2220 | Excel import no longer changes | Major |
GWP-1821 | Ontologies are no longer merged unexpectedly during project import. | Major |
GWP-1724 | Project archives no longer contain unintended extra classes. | Major |
GWP-2386 | Counts of classes, attributes, and relations in ontology and custom-scheme views are now correct. | Medium |
GWP-2538 | Snapshot archives now load as intended after project deletion. | Medium |
GWP-2863 | Pick lists are now showing the contained concepts correctly. | Medium |
GWP-2406 | Tabular import no longer omits descendants in polyhierarchies. | Medium |
GWP-1976 | RDF/JSON export no longer returns an empty object when concept data fields are excluded. | Medium |
GWP-2446 | API creation of definition literals containing double quotation marks now works as intended. | Minor |
GWP-2677 | Workflow Dashboard search now scans concept schemas as intended. | Minor |
GWP-2098 | Fixes relation clashes not being visible in the Graph Modeling interface. | Minor |
GWP-2224 | Left column on the landing page is now correctly displayed. | Minor |
GWP-1530 | Duplicate ontology classes, relations, and attributes after project archive import are now fixed. | Minor |
GWP-2426 | The Corpus Search link now opens correctly from the Applications menu. | Minor |
Platform Components
Component | Version |
|---|---|
GraphDB | 11.4.3 |
Add-ons
Add-on | Version |
|---|---|
ADF | 1.9.0 |
Semantic Workbench | 2.5.0 |
GraphViews | 1.0.1 |
Mirror App | 2.5.0 |
UnifiedViews | 10.2.3 |
Third-Party Infrastructure & Services
Service | Version |
|---|---|
Apache Tomcat | 11.0.22 |
Apache Spark | 4.1.1 |
Keycloak | 25.0.6 |
Elasticsearch | 9.3.8 |
LangChain4j | 1.12.2 |
Core Technologies & Frameworks
Framework | Version |
|---|---|
Java | 21 |
Spring Core | 6.2.19 |
Spring Security | 6.5.9 |
RDF4J | 5.2.2 |
Lucene | 9.9.2 |
CVE | Description | Severity (CVSSv3) |
|---|---|---|
Perl heap buffer overflow compiling regex with repeated fixed string (32-bit) | Critical 9.8 | |
perl Archive::Tar path traversal via crafted symlinks | Critical 9.1 | |
ncurses infocmp stack buffer overflow | High 7.8 | |
MIT krb5 NULL pointer dereference in NegoEx mechanism | High 7.5 | |
MIT krb5 integer underflow / OOB read in NegoEx mechanism | High 7.5 | |
Spring Data Commons DoS via crafted property path strings | High 7.5 | |
Spring Data Commons DoS via cache exhaustion from attacker strings | High 7.5 | |
Spring MVC/WebFlux DoS resolving static resources | High 7.5 | |
Spring Framework ReDoS in AntPathMatcher | High 7.5 | |
Spring Framework algorithmic DoS via crafted SpEL expressions | High 7.5 | |
Spring Framework DoS via unbounded cache growth in SpEL evaluation | High 7.5 | |
gzip LZH decompression global buffer overflow via shared state reuse | High 7.5 | |
perl Archive::Tar arbitrary file modification via crafted hardlinks | High 7.5 | |
Apache HttpComponents Core DoS via oversized HTTP/2 HPACK header blocks | High 7.5 | |
Netty DoS via SPDY SETTINGS frame processing (map amplification) | High 7.5 | |
Netty DoS via SPDY header decompression amplification | High 7.5 | |
Netty DoS via memory exhaustion in SPDY-to-HTTP codec (unreleased ByteBuf) | High 7.5 | |
Netty CORS short-circuit bypass via null Origin header | High 7.5 | |
Netty HTTP/3 memory exhaustion via unbounded reserved-frame buffering | High 7.5 | |
Netty HTTP/2 DoS via DATA frame ByteBuf memory leak in decompressor | High 7.5 | |
Netty memory exhaustion via unbounded acceptEncodingQueue (decompression bomb) | High 7.5 | |
Netty infinite loop in bzip2 decoder (Bzip2BlockDecompressor) | High 7.5 | |
Netty DoS via memory leak decoding malformed DNS domain names | High 7.5 | |
Spring Framework XSS via incorrect JavaScriptUtils escaping | High 7.1 | |
Spring Framework SSRF via incorrect host parsing in UriComponentsBuilder | Medium 6.5 | |
glibc incorrect DNS response parsing via crafted DNS server response | Medium 6.5 | |
GNU Wget memory corruption via crafted Metalink URL | Medium 6.5 | |
glibc app crash/uninitialized memory read via crafted DNS response | Medium 6.5 | |
Spring MVC/WebFlux open redirect via crafted "redirect:" link | Medium 6.1 | |
Spring MVC XSS via user-supplied values in JSP form tags | Medium 6.1 | |
Wget SSRF via unvalidated FTP PASV response IP | Medium 5.9 | |
Spring Data Commons DoS (StackOverflow) parsing Sort params | Medium 5.9 | |
Spring Data Commons DoS via crafted request with @ProjectedPayload | Medium 5.9 | |
Spring MVC/WebFlux information disclosure resolving static resources | Medium 5.9 | |
Spring MVC/WebFlux information disclosure via path traversal | Medium 5.9 | |
glibc OOB write via TSIG record processing (ns_printrrf/ns_printrr) | Medium 5.9 | |
GNU Wget heap buffer overflow via server-supplied filename (convert_fname) | Medium 5.9 | |
GNU Wget heap buffer overflow via crafted HTML attribute encoding | Medium 5.9 | |
Netty CRLF injection via multipart filename in HttpPostRequestEncoder | Medium 5.7 | |
GNU Tar path traversal via crafted archive symlinks | Medium 5.6 | |
SQLite DoS via NULL pointer dereference on malformed changeset | Medium 5.5 | |
nghttp2 HTTP request/response smuggling via ambiguous Upgrade requests | Medium 5.4 | |
Spring MVC/WebFlux DoS via static-resource cache poisoning | Medium 5.3 | |
Spring MVC/WebFlux DoS via slow static-resource resolution (Windows) | Medium 5.3 | |
glibc DoS via iconv() with IBM1390/IBM1399 character sets | Medium 5.3 | |
Spring SpEL allows unintended zero-arg method invocation | Medium 5.3 | |
Spring MVC/WebFlux multipart request smuggling | Medium 5.3 | |
GNU Wget integer overflow in Content-Range header parsing | Medium 5.3 | |
Netty protocol version confusion via lax WebSocket handshaker (V07/V08) | Medium 5.3 | |
Netty improper header neutralization allows duplicate/conflicting Host headers | Medium 5.3 | |
krb5 integer underflow in berval2tl_data() OOB read | Medium 5.0 | |
glibc heap buffer overflow in scanf with %mc and large width | Medium 5.0 | |
GNU tar hidden file injection via crafted archives | Medium 5.0 | |
glibc info disclosure/DoS via ungetwc() with overlapping wide char encodings | Medium 5.0 | |
Linux-PAM plaintext password recovery via timing discrepancy in pam_userdb | Medium 4.8 | |
libcurl use-after-free in HTTP/2 stream-dependency cleanup | Medium 4.7 | |
gzip gzexe arbitrary file overwrite via insecure temp file (TOCTOU) | Medium 4.7 | |
glibc invalid DNS hostname returned via gethostbyaddr functions | Medium 4.0 | |
systemd-oomd path traversal allows killing arbitrary processes | N/A | |
systemd-homed local privilege escalation via group addition | N/A | |
SQLite information disclosure via Session Extension changeset merge | N/A |
CVE | Description | Severity |
|---|---|---|
netty: info disclosure/data manipulation due to improper CNAME record validation | Critical 10 | |
netty: insufficient bailiwick validation for NS records | Critical 10 | |
netty: HTTP request smuggling via improper handling of conflicting HTTP/1.0 headers | Critical 9.8 | |
netty: high-integrity-impact due to improper DNS domain name constraint enforcement | Critical 9.1 | |
netty: incorrect HTTP response parsing leads to data confusion | Critical 9.1 | |
openjdk: improve HTTP client header handling (Oracle CPU 2025-07) | High 8.6 | |
openjdk: better glyph drawing (Oracle CPU 2025-07) | High 8.1 | |
openjdk: glyph out-of-memory access and crash (Oracle CPU 2025-07) | High 8.1 | |
glibc: integer overflow in memalign leads to heap corruption | High 8.1 | |
libpng: heap buffer overflow in png_set_quantize | High 8.1 | |
netty-handler: IPv6 subnet rule bypass due to incorrect masking operation | High 8.1 | |
libpng: information disclosure/DoS via integer truncation | High 7.8 | |
sqlite: integer truncation | High 7.7 | |
libpng: info disclosure/DoS via OOB read/write in Neon palette expansion | High 7.6 | |
bouncycastle: GOSTCTR implementation unable to process >255 blocks correctly | High 7.5 | |
netty-handler: SslHandler doesn't correctly validate packets, can lead to native crash | High 7.5 | |
netty-codec-http: request smuggling via incorrect parsing of chunk extensions | High 7.5 | |
netty-codec: BrotliDecoder vulnerable to DoS via zip-bomb style attack | High 7.5 | |
p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters | High 7.5 | |
openjdk: enhance certificate checking (Oracle CPU 2026-01) | High 7.5 | |
openjdk: enhance Path Factories redux (Oracle CPU 2026-04) | High 7.5 | |
giflib: DoS via buffer overflow in EGifGCBToExtension | High 7.5 | |
libpng: arbitrary code execution due to use-after-free | High 7.5 | |
netty: request smuggling via incorrect parsing of HTTP/1.1 chunked TE extension values | High 7.5 | |
netty: DoS via HTTP/2 CONTINUATION frame flood | High 7.5 | |
openjdk: enhance TLS connection handling (Oracle CPU 2026-04) | High 7.5 | |
micrometer: DoS via specially crafted HTTP requests (micrometer-jetty11/12) | High 7.5 | |
Little CMS (lcms2, bundled in JDK): info disclosure/DoS via integer overflow in CubeSize | High 7.5 | |
netty: HTTP header injection via HttpProxyHandler disabled validation | High 7.5 | |
netty: DoS via excessive memory allocation in LZ4FrameDecoder | High 7.5 | |
netty: request smuggling via malformed Transfer-Encoding parsing | High 7.5 | |
netty: DoS via unbounded memory allocation in HTTP content decompression | High 7.5 | |
netty-codec-haproxy: DoS via malformed HAProxy message | High 7.5 | |
netty-handler: DoS due to eager buffer allocation in TLS handshake | High 7.5 | |
openjdk: enhance Jar handling (Oracle CPU 2026-07) | High 7.5 | |
netty-codec-http2: DoS due to resource leak | High 7.5 | |
netty-codec-haproxy: HAProxy PROXY protocol v2 codec DoS via memory leak | High 7.5 | |
netty-handler: improper trust manager handling leads to hostname verification bypass | High 7.5 | |
netty-codec-http: DoS via SPDY SETTINGS frame processing | High 7.5 | |
netty-codec-http: DoS via SPDY header decompression amplification | High 7.5 | |
netty-codec-haproxy: DoS via crafted PROXY protocol v2 message | High 7.5 | |
bouncycastle: PKIX draft CompositeVerifier accepts empty signature sequence as valid | High 7.5 | |
netty-codec-http: DoS via memory exhaustion in SPDY-to-HTTP codec | High 7.5 | |
netty-codec-http: security control bypass allows unauthorized requests via null origin… | High 7.5 | |
netty-codec-http2: DoS via HTTP/2 DATA frame memory leak | High 7.5 | |
netty-codec-http: protocol version confusion (WebSocket) | High 7.5 | |
netty-codec-http: memory exhaustion (decompression bomb) | High 7.5 | |
netty-codec-compression: infinite loop in bzip2 handling | High 7.5 | |
netty-codec-dns: DoS via memory leak in DNS record decoder with malformed domain names | High 7.5 | |
openjdk: better TLS connection support (Oracle CPU 2025-04) | High 7.4 | |
ncurses: segfaulting OOB read | High 7.1 | |
giflib: heap-buffer overflow in DumpScreen2RGB (bundled in JDK) | High 7.1 | |
libpng: buffer overflow (bundled in JDK) | High 7.1 | |
libpng: heap buffer overflow (bundled in JDK) | High 7.1 | |
libpng: out-of-bounds read in png_image_read_composite | High 7.1 | |
libpng: DoS/information disclosure via heap buffer over-read | High 7.1 | |
acl: symlink traversal privilege escalation via libacl functions | High 7.1 | |
glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH | High 7.0 | |
libcap: privilege escalation via TOCTOU race condition in cap_set_file() | High 7 | |
netty DNS resolver: DNS cache poisoning via predictable transaction IDs | Medium 6.8 | |
netty-codec-http: request smuggling via CRLF injection | Medium 6.5 | |
bouncycastle: LDAP injection in LDAPStoreHelper.java | Medium 6.5 | |
netty: HTTP request smuggling via URI manipulation and CRLF injection | Medium 6.5 | |
netty: request smuggling via chunk-size parser integer overflow | Medium 6.5 | |
glibc: incorrect DNS response parsing via crafted DNS server response | Medium 6.5 | |
netty CorsHandler setVaryHeader replaces Vary headers with Origin, leaking cached… | Medium 6.5 | |
netty-codec-http: CRLF injection via multipart filename in HttpPostRequestEncoder | Medium 6.5 | |
openjdk: improve certification checking (Oracle CPU 2026-07) | Medium 6.5 | |
glibc: application crash/uninitialized memory read via crafted DNS response | Medium 6.5 | |
acl: TOCTOU symlink traversal via getfacl/setfacl | Medium 6.3 | |
p11-kit: stack exhaustion via unbounded recursion in RPC attribute parsing | Medium 6.2 | |
jquery: untrusted code execution via | Medium 6.1 | |
openjdk: improve HttpServer request handling (Oracle CPU 2026-01) | Medium 6.1 | |
libtasn1: DoS via stack-based buffer overflow in asn1_expend_octet_string | Medium 5.9 | |
glibc: | Medium 5.9 | |
openjdk: enhance certificate handling (Oracle CPU 2025-10) | Medium 5.9 | |
openjdk: enhance TLS certificate handling (Oracle CPU 2026-07) | Medium 5.9 | |
glibc: out-of-bounds write via TSIG record processing | Medium 5.9 | |
openjdk: enhance Buffered Image handling (Oracle CPU 2025-04) | Medium 5.6 | |
glibc: vector register overwrite bug | Medium 5.6 | |
netty: denial of service attack on Windows apps using Netty | Medium 5.5 | |
glibc: buffer overflow in | Medium 5.5 | |
netty: denial of service attack on Windows apps using Netty | Medium 5.5 | |
netty-codec-haproxy: improper CR/LF neutralization | Medium 5.5 | |
libtasn1: inefficient DER decoding, potential remote DoS | Medium 5.3 | |
bouncycastle: denial of service | Medium 5.3 | |
glibc: information disclosure via zero-valued network query | Medium 5.3 | |
openjdk: improve Kerberos credentialing (Oracle CPU 2026-04) | Medium 5.3 | |
openjdk: enhance certificate chain validation (Oracle CPU 2026-04) | Medium 5.3 | |
freetype: information disclosure/DoS via crafted font files | Medium 5.3 | |
glibc: DoS via | Medium 5.3 | |
openjdk: improve DTLS handshaking (Oracle CPU 2026-07) | Medium 5.3 | |
openjdk: enhance XBM image support (Oracle CPU 2026-07) | Medium 5.3 | |
openjdk: enhance Jar file processing (Oracle CPU 2026-07) | Medium 5.3 | |
netty-codec-http2: DoS via uncontrolled HTTP/2 concurrent streams | Medium 5.3 | |
netty-codec-http: data manipulation via request-boundary confusion in HttpObjectDecoder | Medium 5.3 | |
netty-codec-http2: DoS due to HTTP/2 max header size handling | Medium 5.3 | |
netty-codec-http2: improper header neutralization | Medium 5.3 | |
glibc: heap buffer overflow in scanf with %mc format specifier and large width | Medium 5 | |
glibc: info disclosure/DoS via ungetwc with wide character encodings | Medium 5 | |
JDK: integer conversion error leads to incorrect range check (8332644) | Medium 4.8 | |
openjdk: enhance array handling (Oracle CPU 2025-01) | Medium 4.8 | |
openjdk: improve compiler transformations (Oracle CPU 2025-04) | Medium 4.8 | |
openjdk: enhance TLS protocol support (Oracle CPU 2025-07) | Medium 4.8 | |
openjdk: enhance Path Factories (Oracle CPU 2025-10) | Medium 4.8 | |
openjdk: improve JMX connections (Oracle CPU 2026-01) | Medium 4.8 | |
coreutils: heap buffer under-read in | Medium 4.4 | |
glibc: double free | Medium 4.2 | |
glibc: invalid DNS hostname returned via gethostbyaddr functions | Medium 4 | |
netty: DoS due to file descriptor leak in SCM_RIGHTS message handling | Medium 4 | |
JDK: HTTP client improper handling of maxHeaderSize (8328286) | Low 3.7 | |
JDK: array indexing integer overflow (8328544) | Low 3.7 | |
JDK: unbounded allocation leads to OOM error (8331446) | Low 3.7 | |
openjdk: enhance String handling (Oracle CPU 2025-10) | Low 3.7 | |
openjdk: enhance Zip file reading (Oracle CPU 2026-04) | Low 3.7 | |
openjdk: enhance JPEG handling (Oracle CPU 2026-07) | Low 3.7 | |
openjdk: enhance AWT ImagingLib (Oracle CPU 2026-07) | Low 3.7 | |
openjdk: enhance crypto algorithm support (Oracle CPU 2026-04) | Low 2.9 | |
openjdk: enhance key generation (Oracle CPU 2026-04) | Low 2.9 |
CVE | Description | Severity |
|---|---|---|
Netty info disclosure/data manipulation due to improper CNAME validation | Critical 10.0 | |
Netty insufficient bailiwick validation for NS records | Critical 10.0 | |
glib GVariant parser buffer underflow leads to heap corruption | Critical 9.8 | |
GnuTLS authentication bypass via NUL character in username (RSA-PSK) | Critical 9.8 | |
Netty HTTP request smuggling via conflicting HTTP/1.0 headers | Critical 9.8 | |
GnuTLS DoS via DTLS zero-length fragment | Critical 9.1 | |
OpenSSL CMS AuthEnvelopedData processing may accept forged messages | Critical 9.1 | |
Netty high integrity impact via improper DNS domain name constraint enforcement | Critical 9.1 | |
Netty incorrect HTTP response parsing leads to data confusion | Critical 9.1 | |
OpenSSL AES-OCB IV ignored on EVP_Cipher() path | Critical 9.1 | |
GnuTLS cert validation bypass due to oversized Subject Alternative Name | High 8.2 | |
GnuTLS info disclosure via heap overread in RSA key exchange (PKCS#11) | High 8.2 | |
Netty IPv6 subnet rule bypass due to incorrect masking operation | High 8.1 | |
OpenSSL heap use-after-free in PKCS7_verify() | High 8.1 | |
systemd arbitrary code execution/DoS via spurious IPC API call data | High 7.8 | |
libsolv heap buffer overflow in repopagestore via unchecked .solv decompression | High 7.8 | |
BC-JAVA GOSTCTR implementation fails beyond 255 blocks | High 7.5 | |
p11-kit NULL dereference via C_DeriveKey with NULL parameters | High 7.5 | |
nghttp2 DoS via malformed HTTP/2 frames after session termination | High 7.5 | |
OpenSSL NULL pointer dereference in CMS EnvelopedData processing | High 7.5 | |
GnuTLS DoS via heap buffer overflow in DTLS handshake fragment reassembly | High 7.5 | |
Netty request smuggling via HTTP/1.1 chunked transfer encoding extension parsing | High 7.5 | |
Netty DoS via HTTP/2 CONTINUATION frame flood | High 7.5 | |
OpenSSL heap buffer over-read in ASN.1 decoding (DoS/info disclosure) | High 7.5 | |
OpenSSL unbounded memory growth in QUIC PATH_CHALLENGE handler | High 7.5 | |
Log4j Core log injection via CRLF sequences from config attribute renames | High 7.5 | |
Log4j 1-to-2 bridge DoS via improper XML escaping | High 7.5 | |
Log4j Core invalid XML output causes DoS in logging | High 7.5 | |
MIT Kerberos 5 DoS via NULL pointer dereference in NegoEx mechanism | High 7.5 | |
MIT Kerberos 5 DoS via integer underflow and out-of-bounds read | High 7.5 | |
GnuTLS DoS via DTLS packet reordering vulnerability | High 7.5 | |
Netty HTTP header injection via HttpProxyHandler disabled validation | High 7.5 | |
Netty DoS via excessive memory allocation in LZ4FrameDecoder | High 7.5 | |
Netty request smuggling via malformed Transfer-Encoding parsing | High 7.5 | |
Netty DoS via unbounded memory allocation in HTTP content decompression | High 7.5 | |
libarchive info disclosure via heap out-of-bounds read in RAR archive processing | High 7.5 | |
Netty DoS due to eager buffer allocation in TLS handshake | High 7.5 | |
Netty codec-http2 DoS due to resource leak | High 7.5 | |
Netty improper trust manager handling bypasses hostname verification | High 7.5 | |
libarchive arbitrary code execution via integer overflow in ISO9660 image processing | High 7.5 | |
BouncyCastle PKIX CompositeVerifier accepts empty signature sequence as valid | High 7.5 | |
OpenSSL PKCS#12 PBMAC1 accepted with short HMAC keys | High 7.4 | |
GnuTLS policy bypass via case-sensitive nameConstraints comparison | High 7.4 | |
GnuTLS security bypass due to incorrect name constraint handling | High 7.4 | |
GnuTLS cert validation bypass via improper handling of URI/SRV SANs | High 7.1 | |
libcap privilege escalation via TOCTOU race in cap_set_file() | High 7.0 | |
Netty DNS resolver cache poisoning via predictable transaction IDs | Medium 6.8 | |
GnuTLS use-after-free in gnutls_pkcs11_token_set_pin | Medium 6.6 | |
glib GIO attribute escaping integer overflow causes heap buffer overflow | Medium 6.5 | |
BC-JAVA LDAP injection in LDAPStoreHelper.java | Medium 6.5 | |
Netty request smuggling via chunk size parser integer overflow | Medium 6.5 | |
glibc incorrect DNS response parsing via crafted DNS server response | Medium 6.5 | |
jackson-databind @JsonIgnore bypass in Java Records | Medium 6.5 | |
OpenSSL multi-RecipientInfo Bleichenbacher oracle in CMS/PKCS7 decrypt | Medium 6.3 | |
libtasn1 DoS via stack-based buffer overflow in asn1_expend_octet_string | Medium 5.9 | |
OpenSSL info disclosure from uninitialized memory via invalid RSA public key | Medium 5.9 | |
Log4j Core MITM via incomplete hostname verification | Medium 5.9 | |
OpenSSL NULL pointer dereference in QUIC server initial packet handling | Medium 5.9 | |
OpenSSL trust-anchor substitution via cert/issuer typo in CMP rootCaKeyUpdate | Medium 5.9 | |
OpenSSL FFC-DH peer validation uses attacker-supplied q | Medium 5.9 | |
OpenSSL DoS via heap out-of-bounds read in CMS password-based decryption | Medium 5.9 | |
libxml2 buffer over-read in xmlHTMLPrintFileContext (xmllint) | Medium 5.5 | |
OpenSSL heap buffer overflow via signed integer overflow in Unicode output sizing | Medium 5.5 | |
glibc DoS via iconv() with IBM1390/IBM1399 character sets | Medium 5.3 | |
Netty HTTP request smuggling via URI manipulation and CRLF injection | Medium 5.3 | |
GnuTLS memory corruption via off-by-one error in PKCS#12 bag handling | Medium 5.3 | |
OpenSSL possible NULL dereference in password-based CMS decryption | Medium 5.3 | |
OpenSSL NULL pointer dereference in CRMF EncryptedValue decryption | Medium 5.3 | |
Netty DoS via uncontrolled HTTP/2 concurrent streams | Medium 5.3 | |
Netty data manipulation via request-boundary confusion in HttpObjectDecoder | Medium 5.3 | |
Netty DoS due to HTTP/2 max header size handling | Medium 5.3 | |
jackson-databind info disclosure via eager DNS resolution | Medium 5.3 | |
glibc heap buffer overflow in scanf with %mc format specifier and large width | Medium 5.0 | |
Log4j Core info disclosure via missing TLS hostname verification | Medium 4.8 | |
coreutils sort heap buffer under-read via key specification | Medium 4.4 | |
glibc invalid DNS hostname returned via gethostbyaddr functions | Medium 4.0 | |
GnuTLS accepts revoked server certs via crafted multi-record OCSP response | Low 3.7 | |
OpenSSL incorrect tag processing for empty messages in AES-GCM-SIV/AES-SIV | Low 3.7 | |
GnuTLS info disclosure via timing side-channel in PKCS#7 padding removal | Low 3.7 | |
libxml2 stack buffer overflow in xmllint interactive shell command handling | Low 2.5 |