Debian Hsqldb vulnerabilities
3 known vulnerabilities affecting debian/hsqldb.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2023-1183MEDIUMCVSS 5.0fixed in hsqldb 2.7.1-1+deb12u1 (bookworm)2023
CVE-2023-1183 [MEDIUM] CVE-2023-1183: hsqldb - A flaw was found in the Libreoffice package. An attacker can craft an odb contai...
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.
Scope: local
bookworm: resolved (fixed in 2.7.1-1+deb12u1)
bullseye: resolved (fixed in 2.5.1-1+deb11u2)
forky: resolved (fixed
debian
CVE-2022-41853HIGHCVSS 8.0fixed in hsqldb 2.7.1-1 (bookworm)2022
CVE-2022-41853 [HIGH] CVE-2022-41853: hsqldb - Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL...
Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "
debian
CVE-2007-4575CRITICALCVSS 9.3fixed in hsqldb 1.8.0.9-1 (bookworm)2007
CVE-2007-4575 [CRITICAL] CVE-2007-4575: hsqldb - HSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows us...
HSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code via crafted database documents, related to "exposing static java methods."
Scope: local
bookworm: resolved (fixed in 1.8.0.9-1)
bullseye: resolved (fixed in 1.8.0.9-1)
forky: resolved (fixed in 1.8.0.9-1)
sid: resolved (fixed i
debian