Package impact

java Maven / log4j:log4j

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-23305 critical 9.8 9.8 4y ago SQL Injection in Log4j 1.2.x
CVE-2019-17571 critical 9.8 9.8 7y ago Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization ga…
CVE-2022-23307 high 8.8 8.8 4y ago Deserialization of Untrusted Data in Apache Log4j
CVE-2022-23302 high 8.8 8.8 4y ago Deserialization of Untrusted Data in Log4j 1.x
CVE-2021-4104 high 8.0 5y ago JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectio…
CVE-2023-26464 unknown 3y ago Apache Log4j 1.x (EOL) allows Denial of Service (DoS)