stanford CVE 脆弱性と CVE 一覧(8)

製品(CPE): — CVE 件数: 8

stanford 脆弱性概要

stanford 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。

Historical issues mainly involve vendor risk xxe and related security problems, affecting vendor surface software deployment and vendor surface production workloads scenarios.

掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。

脆弱性分布の推移(直近24か月)

表示中 18 / 8 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2023-39020 stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStream. This vulnerability is exploited via passing an unchecked argument. [email protected] 9.8 0.10% 2023-07-28 2024-11-21
CVE-2021-44550 An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159). [email protected] 9.8 0.45% 2022-02-24 2024-11-21
CVE-2022-0239 corenlp is vulnerable to Improper Restriction of XML External Entity Reference [email protected] 9.8 0.04% 2022-01-17 2026-04-16
CVE-2022-0198 corenlp is vulnerable to Improper Restriction of XML External Entity Reference [email protected] 7.1 0.18% 2022-01-13 2024-11-21
CVE-2021-3869 corenlp is vulnerable to Improper Restriction of XML External Entity Reference [email protected] 7.5 0.31% 2021-10-19 2024-11-21
CVE-2021-3878 corenlp is vulnerable to Improper Restriction of XML External Entity Reference [email protected] 9.8 0.31% 2021-10-15 2025-09-08
CVE-2013-2106 webauth before 4.6.1 has authentication credential disclosure [email protected] 7.5 0.40% 2019-12-03 2024-11-21
CVE-2009-2945 weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history. [email protected] 4.3 0.23% 2009-09-15 2026-04-23
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence