CVE Tools

Mortbay

8 CVEs tracked since 2009. Since May 2009, none of them reached CISA KEV.

Mortbay CVEs per month

May 2009 to Dec 2011. Point at a month, or focus the strip and use the arrow keys.
Mortbay CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2009-0520
2009-06null or fewer
2009-07null or fewer
2009-08null or fewer
2009-09null or fewer
2009-1010
2009-11null or fewer
2009-12null or fewer
2010-0140
2010-02null or fewer
2010-03null or fewer
2010-04null or fewer
2010-05null or fewer
2010-06null or fewer
2010-07null or fewer
2010-08null or fewer
2010-09null or fewer
2010-10null or fewer
2010-11null or fewer
2010-12null or fewer
2011-01null or fewer
2011-02null or fewer
2011-03null or fewer
2011-04null or fewer
2011-05null or fewer
2011-06null or fewer
2011-07null or fewer
2011-08null or fewer
2011-09null or fewer
2011-10null or fewer
2011-11null or fewer
2011-1210

Products

The products that kept showing up in Mortbay's monthly top three, with their CVEs summed over those months.

  1. Jetty84 months

Latest CVEs

The 11 most recently published vulnerabilities affecting Mortbay.

  1. CVE-2009-5049WebApp JSP Snoop page XSS in jetty though 6.1.21.6.1
  2. CVE-2009-5048Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20.6.1
  3. CVE-2011-4461Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of servi...5.3
  4. CVE-2009-4610Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to jsp/dump.jsp in the JSP...4.3
  5. CVE-2009-4612Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_IN...4.3
  6. CVE-2009-4609The Dump Servlet in Mort Bay Jetty 6.x and 7.0.0 allows remote attackers to obtain sensitive information about internal variables and other data via a request to a URI ending in /dump/, as demonstr...5.0
  7. CVE-2009-4611Mort Bay Jetty 6.x through 6.1.22 and 7.0.0 writes backtrace data without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arb...7.5
  8. CVE-2009-3579Cross-site scripting (XSS) vulnerability in the CookieDump.java sample application in Mort Bay Jetty 6.1.19 and 6.1.20 allows remote attackers to inject arbitrary web script or HTML via the Value p...4.3
  9. CVE-2009-1523Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal ...5.0
  10. CVE-2009-1524Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web script or HTML via a directory listing request containing a ; (semicolon) ch...4.3
  11. CVE-2005-3747Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters....5.0

The record

Peak rank
#17 in Jan 2010
Busiest month shown
Jan 2010, 4 CVEs
Months with a KEV entry
0 since May 2009
Monthly snapshots
4 since 2009
Mortbay's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store