- 0-day exploit for the Apache plugin for Oracle WebLogic
- Tomcat exploit published (fixed in 6.0.18)
- Fix for vulnerability in Nokia S40 J2ME implementations
- Anybody know VundoFix?
- JBoss users may be vulnerable to Tomcat issue
- Best not use Tomcat's manager application
- CVE-2008-3271 - Apache Tomcat information disclosure via RemoteFilterValve
- CVE-2008-4008: Apache plugin for Oracle WebLogic Server (formerly BEA WebLogic)
- CVE-2008-4541: Heap-based buffer overflow in the FTP subsystem in Sun Java System Web
- CVE-2008-4678: IBM WebSphere (WAS) 6.0.2 before 6.0.2.31 remote DoS
- CVE-2008-4679: IBM WebSphere revoked X509 certificates in SOAP aren't rejected
- CVE-2008-4747: Sun Java System LDAP JDK before 4.20 local information disclosure
- CVE-2008-4910: Java web start remote code execution
- Openfire Server Multiple Vulnerabilities
- CVE-2008-5098: Sun Java System Messaging Server XSS vulnerability
- CVE-2008-5114-CVE-2008-5118: Sun Java System Identity Manager multiple vulnerabilties
- Tomcat Privilege Escalation on Windows
- candidate CVE-2008-5266: (XSS) vulnerability in GlassFish 2 webadmin interface
- CVE-2004-2320: still alive at 4 years of age?
- iDefense Labs: Sun Java JRE TrueType Font Parsing Heap Overflow Vulnerability
- iDefense Labs: Sun Java Web Start GIF Decoding Memory Corruption Vulnerability
- CVE-2008-5411,CVE-2008-5412, CVE-2008-5413, CVE-2008-5414: security patch 7.0.0.1 out
- CVE-2008-1232: Cross-site scripting (XSS) vulnerability in Apache Tomcat
- advance notice: patches on the 13th for Oracle application servers and more
- CVE-2008-5662: Multiple buffer overflows in Sun Java Wireless Toolkit (WTK) for CLDC
- If you have the chance: update to Java 1.6.0_11 or 1.5.0_17
- Atlassian JIRA Remote Security Bypass Vulnerability
- Reminder: Oracle's critical patches are on-line
- Multiple Openfire Vulnerabilities fixed in 3.6.3
- CVE-2008-5550: open redirect vulnerability in Sun Java Web Console
- CVE-2009-0278: Sun Java System Application Server configuration files exposed via a m
- IBM WebSphere Application Server Arbitrary File Information Disclosure Vulnerability
- Sun Java System Access Manager Username Enumeration Weakness
- SQL injection vulnerability in Oracle Enterprise Manager
- WebSphere fixes available for several CVE's
- Apple Java update fixes CVE-2008-2086, CVE-2008-5340, CVE-2008-5342 and CVE-2008-5343
- Openfire 3.6.3 fixes CVE-2009-0496 and CVE-2009-0497
- Cross Site Scripting Vulnerability JOnAS 4.10.3
- CVE-2009-0781: Cross-site scripting vulnerability in Tomcat's calendar example
- CVE-2009-0027: Fix for XML file disclosure issue in JBoss EAP
- More Java vulnerabilities fixed, details to follow
- CVE-2009-0439: local privilege escalation in IBM WebSphere MQ
- CVE-2009-0609: Sun Java System Directory Proxy Server denial of service
- Openfire password change vulnerability
- How to stop Java security warning message from popping up?
- I Need Help Fixing Some Vulnerabilities on Some Applications?
- Apache Archiva Multiple XSS vulnerability
- Apache Archiva Multiple CSRF vulnerability
- Tabnapping Phishing Proof Of Concept
- Sybase EAServer Web Service Remote Installation Vulnerability
- CVE-2011-2474 (easerver)
- Sybase EAServer Remote Directory Traversal Vulnerability
- Oracle HTTP Server Header Cross Site Scripting
- CVE-2011-0862 (jre)
- CVE-2011-0817 (jre)
- CVE-2011-0815 (jre)
- CVE-2011-0814 (jre)
- CVE-2011-0802 (jre)
- CVE-2011-0788 (jre)
- CVE-2011-0786 (jre)
- CVE-2011-0863 (jre)
- CVE-2011-0864 (jre)
- CVE-2011-0865 (jre)
- CVE-2011-0873 (jre)
- CVE-2011-0872 (jre)
- CVE-2011-0871 (jre)
- CVE-2011-0869 (jre)
- CVE-2011-0868 (jre)
- CVE-2011-0867 (jre)
- CVE-2011-0866 (jre)
- IBM WebSphere Application Server Cross Site Request Forgery
- Oracle Java Runtime Environment FileDialog.show() Heap Buffer Oveflow Vulnerability
- Oracle Java Soundbank Heap Buffer Overflow Vulnerability
- Oracle Java Soundbank Stack Buffer Overflow
- CVE-2011-0786 (jdk, jre)
- CVE-2011-0788 (jdk, jre)
- CVE-2011-0802 (jdk, jre)
- CVE-2011-0814 (jdk, jre)
- CVE-2011-0815 (jdk, jre)
- CVE-2011-0817 (jdk, jre)
- CVE-2011-0862 (jdk, jre)
- CVE-2011-0863 (jdk, jre)
- CVE-2011-0864 (jdk, jre)
- CVE-2011-0865 (jdk, jre)
- CVE-2011-0873 (jdk, jre)
- CVE-2011-0872 (jdk, jre)
- CVE-2011-0871 (jdk, jre)
- CVE-2011-0869 (jdk, jre)
- CVE-2011-0868 (jdk, jre)
- CVE-2011-0867 (jdk, jre)
- CVE-2011-0866 (jdk, jre)
- CVE-2011-2091 (coldfusion)
- CVE-2011-0629 (coldfusion)
- CVE-2011-2093 (blazeds, livecycle_data_services)
- CVE-2011-2092 (blazeds, livecycle_data_services)
- IBM WebSphere Application Server 7.0.0.13 CSRF Vulnerability
- CVE-2011-2204 (tomcat)
- Spring Source OXM 3.0.4 Command Injection
- CVE-2011-1224 (websphere_mq)
- CVE-2011-1498 (httpclient)
- CVE-2011-2526 (tomcat)
- Java RMI Server Insecure Default Configuration Java Code Execution
- CVE-2011-2754 (web_content_manager, websphere_portal)
- CVE-2010-3271 (websphere_application_server)
- Oracle Sun GlassFish Enterprise Server 2.1.1 Cross Site Scripting
- CVE-2011-1355 (websphere_application_server)
- CVE-2011-1356 (websphere_application_server)
- CVE-2011-2297 (solaris_cluster)
- CVE-2011-2260 (sun_products_suite)
- CVE-2011-1511 (sun_products_suite)
- CVE-2011-0219 (safari, webkit)
- CVE-2011-1484 (jboss_enterprise_application_platform, jboss_enterprise_soa_platform,
- CVE-2009-4139 (network_satellite_server, spacewalk-java)
- CVE-2011-2196 (jboss_enterprise_application_platform, jboss_enterprise_soa_platform,
- Android Browser Cross Application Scripting
- Sun/Oracle GlassFish Server Authenticated Code Execution
- Sun/Oracle GlassFish Server Authenticated Code Execution
- CVE-2011-1357 (websphere_service_registry_and_repository)
- TeeChart Professional ActiveX Control 2010.0.0.3 Trusted Integer Dereference
- CVE-2011-3138 (tivoli_federated_identity_manager, tivoli_federated_identity_manager_b
- CVE-2011-2481 (tomcat)
- CVE-2011-2729 (tomcat, apache_commons_daemon)
- CVE-2011-0527 (tc_server)
- ColdFusion probe.cfm Cross Site Scripting
- Apache Struts < 2.2.0 Remote Command Execution
- Apache Struts < 2.2.0 Remote Command Execution
- Apache Wicket XSS vulnerability
- CVE-2011-2712 (wicket)
- CVE-2011-3190 (tomcat)
- Apache Tomcat Authentication bypass and information disclosure
- CVE-2011-0311 (java, runtimes_for_java_technology)
- CVE-2011-3387 (java)
- CVE-2011-1359 (websphere_application_server)
- Spring Security Header Injection
- CVE-2011-1911 (jasperreports_server_community_project)
- CVE-2011-3577 (websphere_commerce)
- Adobe ColdFusion 7 Cross Site Scripting
- CVE-2011-2894 (springsource_spring_framework, springsource_spring_security)
- JBoss addURL Misconfiguration Attack
- JBoss, JMX Console, misconfigured DeploymentScanner
- Spring Framework and Spring Security serialization-based remoting vulnerabilities
- CVE-2000-1247 (jserv)
- Daytona JBoss Exploitation Kit
- CVE-2011-3559 (communications_server, glassfish_server, java_system_application_serve
- CVE-2011-2319 (fusion_middleware)
- CVE-2011-2320 (fusion_middleware)
- CVE-2011-2255 (fusion_middleware)
- CVE-2011-2318 (fusion_middleware)
- White paper on remote DNS cache poisoning via port exhaustion (using Java applets)
- CVE-2011-3549 (jdk, jre)
- CVE-2011-3548 (jdk, jre)
- CVE-2011-3547 (jdk, jre)
- CVE-2011-3546 (javafx, jdk, jre)
- CVE-2011-3545 (jrockit, jdk, jre)
- CVE-2011-3544 (jdk, jre)
- CVE-2011-3521 (jdk, jre)
- CVE-2011-3516 (jdk, jre)
- CVE-2011-3550 (jdk, jre)
- CVE-2011-3551 (jdk, jre, jrockit)
- CVE-2011-3552 (jdk, jre)
- CVE-2011-3561 (javafx, jdk, jre)
- CVE-2011-3560 (jdk, jre)
- CVE-2011-3558 (jdk, jre)
- CVE-2011-3557 (jdk, jre, jrockit)
- CVE-2011-3556 (jdk, jre, jrockit)
- CVE-2011-3555 (jdk, jre)
- CVE-2011-3554 (jdk, jre)
- CVE-2011-3553 (jdk, jre, jrockit)
- CVE-2011-4171 (websphere_ilog_rule_team_server)
- CVE-2011-1371 (websphere_ilog_rule_team_server)
- CVE-2011-1360 (http_server)
- CVE-2010-0780 (websphere_mq)
- CVE-2011-1368 (websphere_application_server)
- CVE-2009-2747 (websphere_application_server)
- CVE-2009-2748 (websphere_application_server)
- CVE-2009-0905 (websphere_mq)
- CVE-2009-0900 (websphere_mq)
- CVE-2011-3376 (tomcat)
- Adobe ColdFusion 9 Denial Of Service
- CVE-2011-4404 (vcenter_update_manager)
- CVE-2011-1378 (websphere_mq)
- Java Applet Rhino Script Engine Remote Code Execution
- Apache MyFaces 2.0 / 2.1 Information Disclosure
- Java Applet Rhino Script Engine Remote Code Execution
- Red Hat Security Advisory 2011-1798-01
- CVE-2011-2463 (coldfusion)
- CVE-2011-4368 (coldfusion)
- CVE-2011-4084 (tomcat)
- CVE-2011-4461 (jetty)
- CVE-2011-5035 (glassfish_server)
- CVE-2011-5048 (web_experience_factory)
- CVE-2011-4858 (tomcat)
- CVE-2011-4905 (activemq)
- Apache Struts2 File Overwrite / Command Execution
- Oracle GlassFish Server Administration Bypass
- CVE-2011-3206 (jboss_operations_network, rhq)
- CVE-2012-0391 (struts)
- CVE-2012-0392 (struts)
- CVE-2012-0393 (struts)
- Cve-2011-5057
- Cve-2012-0394
- CVE-2011-5057 (struts)
- CVE-2012-0394 (struts)
- CVE-2011-5062 (tomcat)
- CVE-2011-5063 (tomcat)
- CVE-2011-5064 (tomcat)
- CVE-2011-1362 (websphere_application_server)
- CVE-2011-1377 (websphere_application_server)
- CVE-2011-5066 (websphere_application_server)
- CVE-2011-5065 (websphere_application_server)
- CVE-2011-1184 (tomcat)
- CVE-2011-1377 (websphere_application_server)
- CVE-2012-0022 (tomcat)
- CVE-2011-3564 (sun_glassfish_enterprise_server)
- CVE-2011-3566 (fusion_middleware)
- CVE-2012-0077 (fusion_middleware)
- CVE-2012-0081 (glassfish_server)
- CVE-2012-0104 (glassfish_server)
- CVE-2011-3375 (tomcat)
- CVE-2011-1376 (websphere_application_server)
- CVE-2012-0193 (websphere_application_server)
- CVE-2011-4314 (jboss_enterprise_application_platform, kay_framework, openid4java)
- CVE-2011-4608 (jboss_enterprise_application_platform)
- Cross-site scripting (XSS)
- Apache Struts 1.3.10 / 2.0.14 / 2.2.3 Cross Site Scripting