Lucene search

K

Jetty Security Vulnerabilities

cve
cve

CVE-2024-22201

Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to...

7.5CVSS

7.3AI Score

0.0004EPSS

2024-02-26 04:27 PM
116
cve
cve

CVE-2006-2759

jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary script source code via a capital P in the .jsp extension, and probably other mixed case...

6.8AI Score

0.003EPSS

2022-10-03 04:21 PM
51
cve
cve

CVE-2007-6672

Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to bypass protection mechanisms and read the source of files via multiple '/' (slash) characters in the...

7.3AI Score

0.007EPSS

2008-01-08 11:46 AM
33
cve
cve

CVE-2007-5615

CRLF injection vulnerability in Mortbay Jetty before 6.1.6rc0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified...

7.3AI Score

0.01EPSS

2007-12-05 11:46 AM
22
cve
cve

CVE-2007-5613

Cross-site scripting (XSS) vulnerability in Dump Servlet in Mortbay Jetty before 6.1.6rc1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters and...

6.6AI Score

0.006EPSS

2007-12-05 11:46 AM
51
cve
cve

CVE-2007-5614

Mortbay Jetty before 6.1.6rc1 does not properly handle "certain quote sequences" in HTML cookie parameters, which allows remote attackers to hijack browser sessions via unspecified...

6.1AI Score

0.022EPSS

2007-12-05 11:46 AM
43
cve
cve

CVE-2006-6969

Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remote attackers to guess a session identifier through brute force attacks, bypass authentication requirements, and...

7.1AI Score

0.142EPSS

2007-02-07 11:28 AM
21
cve
cve

CVE-2006-2758

Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the same issue as...

6.3AI Score

0.011EPSS

2006-06-02 01:02 AM
27
cve
cve

CVE-2004-2478

Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the...

6.6AI Score

0.023EPSS

2005-08-21 04:00 AM
21
cve
cve

CVE-2004-2381

HttpRequest.java in Jetty HTTP Server before 4.2.19 allows remote attackers to cause denial of service (memory usage and application crash) via HTTP requests with a large...

6.4AI Score

0.021EPSS

2005-08-16 04:00 AM
27
cve
cve

CVE-2002-1178

Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (dot-dot backslash) sequences in an HTTP request to the cgi-bin...

8.1AI Score

0.016EPSS

2004-09-01 04:00 AM
35
cve
cve

CVE-2002-1533

Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters...

5.8AI Score

0.006EPSS

2003-03-31 05:00 AM
26