Mortbay
8 CVEs tracked since 2009. Since May 2009, none of them reached CISA KEV.
Mortbay CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2009-05 | 2 | 0 |
| 2009-06 | null or fewer | |
| 2009-07 | null or fewer | |
| 2009-08 | null or fewer | |
| 2009-09 | null or fewer | |
| 2009-10 | 1 | 0 |
| 2009-11 | null or fewer | |
| 2009-12 | null or fewer | |
| 2010-01 | 4 | 0 |
| 2010-02 | null or fewer | |
| 2010-03 | null or fewer | |
| 2010-04 | null or fewer | |
| 2010-05 | null or fewer | |
| 2010-06 | null or fewer | |
| 2010-07 | null or fewer | |
| 2010-08 | null or fewer | |
| 2010-09 | null or fewer | |
| 2010-10 | null or fewer | |
| 2010-11 | null or fewer | |
| 2010-12 | null or fewer | |
| 2011-01 | null or fewer | |
| 2011-02 | null or fewer | |
| 2011-03 | null or fewer | |
| 2011-04 | null or fewer | |
| 2011-05 | null or fewer | |
| 2011-06 | null or fewer | |
| 2011-07 | null or fewer | |
| 2011-08 | null or fewer | |
| 2011-09 | null or fewer | |
| 2011-10 | null or fewer | |
| 2011-11 | null or fewer | |
| 2011-12 | 1 | 0 |
Products
The products that kept showing up in Mortbay's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 11 most recently published vulnerabilities affecting Mortbay.
- CVE-2009-5049WebApp JSP Snoop page XSS in jetty though 6.1.21.6.1
- CVE-2009-5048Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20.6.1
- CVE-2011-4461Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of servi...5.3
- CVE-2009-4610Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to jsp/dump.jsp in the JSP...4.3
- CVE-2009-4612Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_IN...4.3
- CVE-2009-4609The Dump Servlet in Mort Bay Jetty 6.x and 7.0.0 allows remote attackers to obtain sensitive information about internal variables and other data via a request to a URI ending in /dump/, as demonstr...5.0
- CVE-2009-4611Mort Bay Jetty 6.x through 6.1.22 and 7.0.0 writes backtrace data without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arb...7.5
- CVE-2009-3579Cross-site scripting (XSS) vulnerability in the CookieDump.java sample application in Mort Bay Jetty 6.1.19 and 6.1.20 allows remote attackers to inject arbitrary web script or HTML via the Value p...4.3
- CVE-2009-1523Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal ...5.0
- CVE-2009-1524Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web script or HTML via a directory listing request containing a ; (semicolon) ch...4.3
- CVE-2005-3747Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters....5.0
The record
- Peak rank
- #17 in Jan 2010
- Busiest month shown
- Jan 2010, 4 CVEs
- Months with a KEV entry
- 0 since May 2009
- Monthly snapshots
- 4 since 2009