Vulnerabilities > Restlet

DATE CVE VULNERABILITY TITLE RISK
2017-11-30 CVE-2017-14949 XXE vulnerability in Restlet
Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered.
network
low complexity
restlet CWE-611
5.0
2017-11-30 CVE-2017-14868 XXE vulnerability in Restlet
Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request.
network
low complexity
restlet CWE-611
5.0
2014-10-06 CVE-2014-1868 Unspecified vulnerability in Restlet Framework
Restlet Framework 2.1.x before 2.1.7 and 2.x.x before 2.2 RC1, when using XMLRepresentation or XML serializers, allows attackers to cause a denial of service via an XML Entity Expansion (XEE) attack.
network
low complexity
restlet
5.0
2013-10-10 CVE-2013-4271 Deserialization of Untrusted Data vulnerability in Restlet
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allows remote attackers to execute arbitrary Java code via a serialized object, a different vulnerability than CVE-2013-4221.
network
low complexity
restlet CWE-502
7.5
2013-10-10 CVE-2013-4221 Configuration vulnerability in Restlet
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources using the Java XMLDecoder, which allows remote attackers to execute arbitrary Java code via crafted XML.
network
low complexity
restlet CWE-16
7.5