CVE Security Report Legacy - SICS Naming Service

CVE Security Report Legacy - SICS Naming Service

The report contains data retrieved from the National Vulnerability Database: https://nvd.nist.gov, NPM Public Advisories: https://www.npmjs.com/advisories, and the RetireJS community.

Name Description CWE CVSS v2.0 Severity CVSS v3.0 Severity Dependency
CVE-2024-1597 pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeholder for a string value after the first placeholder; both must be on the same line. By constructing a matching string payload, the attacker can inject SQL to alter the query,bypassing the protections that parameterized queries bring against SQL Injection attacks. Versions before 42.7.2, 42.6.1, 42.5.5, 42.4.4, 42.3.9, and 42.2.28 are affected. CWE-89 CRITICAL postgresql-42.7.0.jar
CVE-2024-7254 Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker. CWE-400 HIGH protobuf-java-3.21.9.jar
CVE-2016-4570 The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. CWE-400 HIGH MEDIUM webservices-extra-api-2.4.10.jar (shaded: jakarta.xml.registry:jakarta.xml.registry-api:1.0.10)
CVE-2016-4571 The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. CWE-400 HIGH MEDIUM webservices-extra-api-2.4.10.jar (shaded: jakarta.xml.registry:jakarta.xml.registry-api:1.0.10)
CVE-2016-4570 The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. CWE-400 HIGH MEDIUM webservices-extra-api-2.4.10.jar (shaded: jakarta.xml.rpc:jakarta.xml.rpc-api:1.1.4)
CVE-2016-4571 The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. CWE-400 HIGH MEDIUM webservices-extra-api-2.4.10.jar (shaded: jakarta.xml.rpc:jakarta.xml.rpc-api:1.1.4)

This report was generated 09.09.2025, 16:56:47 UTC, using dependency-check version: 12.1.1.