Pippo
3 CVEs tracked since 2018. Since Oct 2018, none of them reached CISA KEV.
Pippo CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2018-10 | 3 | 0 |
Products
The products that kept showing up in Pippo's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 5 most recently published vulnerabilities affecting Pippo.
- CVE-2019-5442XML Entity Expansion (Billion Laughs Attack) on Pippo 1.12.0 results in Denial of Service.Entities are created recursively and large amounts of heap memory is taken. Eventually, the JVM process wil...7.5
- CVE-2018-20059jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.9.8
- CVE-2018-18628An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize a SessionData object without checking the objec...9.8
- CVE-2017-18349parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by...9.8
- CVE-2018-18240Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine component does not use XStream's available protection mechanisms to restrict un...9.8
The record
- Peak rank
- #133 in Oct 2018
- Busiest month shown
- Oct 2018, 3 CVEs
- Months with a KEV entry
- 0 since Oct 2018
- Monthly snapshots
- 1 since 2018