Debian Bcel vulnerabilities
2 known vulnerabilities affecting debian/bcel.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2022-42920CRITICALCVSS 9.8fixed in bcel 6.5.0-2 (bookworm)2022
CVE-2022-42920 [CRITICAL] CVE-2022-42920: bcel - Apache Commons BCEL has a number of APIs that would normally only allow changing...
Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode th
debian
CVE-2022-34169HIGHCVSS 7.5fixed in bcel 6.5.0-2 (bookworm)2022
CVE-2022-34169 [HIGH] CVE-2022-34169: bcel - The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue ...
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies o
debian