cbcvebase.

Debian Libcommons-Fileupload-Java vulnerabilities

6 known vulnerabilities affecting debian/libcommons-fileupload-java.

Total CVEs
6
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH5LOW1

Vulnerabilities

Page 1 of 1
CVE-2014-0050P2HIGHCVSS 7.5PoCfixed in libcommons-fileupload-java 1.3.1-1 (bookworm)2014
CVE-2014-0050 [HIGH] CVE-2014-0050: libcommons-fileupload-java - MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apach... MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions. Scope: local bookworm: resolved (fixed in 1.3.1-1) bullsey
debian
CVE-2025-48976P2HIGHCVSS 7.5fixed in libcommons-fileupload-java 1.4-1+deb11u1 (bullseye)2025
CVE-2025-48976 [HIGH] CVE-2025-48976: libcommons-fileupload-java - Allocation of resources for multipart headers with insufficient limits enabled a... Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue. Scope: local bookworm: open bullseye: r
debian
CVE-2023-24998P3HIGHCVSS 7.5fixed in libcommons-fileupload-java 1.4-2 (bookworm)2023
CVE-2023-24998 [HIGH] CVE-2023-24998: libcommons-fileupload-java - Apache Commons FileUpload before 1.5 does not limit the number of request parts ... Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be
debian
CVE-2013-2186P3HIGHCVSS 7.5fixed in libcommons-fileupload-java 1.3-2.1 (bookworm)2013
CVE-2013-2186 [HIGH] CVE-2013-2186: libcommons-fileupload-java - The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BR... The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance. Scope: local bookworm: resolved (fixed in 1.3-2.1) bullseye: resolved (fixed
debian
CVE-2016-3092P3HIGHCVSS 7.5fixed in libcommons-fileupload-java 1.3.2-1 (bookworm)2016
CVE-2016-3092 [HIGH] CVE-2016-3092: libcommons-fileupload-java - The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in ... The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string. Scope: local bookworm: resolved (fixed in 1.3.2-1) bulls
debian
CVE-2013-0248P4LOWCVSS 3.3fixed in libcommons-fileupload-java 1.3-1 (bookworm)2013
CVE-2013-0248 [LOW] CVE-2013-0248: libcommons-fileupload-java - The default configuration of javax.servlet.context.tempdir in Apache Commons Fil... The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack. Scope: local bookworm: resolved (fixed in 1.3-1) bullseye: resolved (fixed in 1.3-1) forky: resolved (fixed in 1.
debian
Debian Libcommons-Fileupload-Java vulnerabilities | cvebase