VYPR

Commons Fileupload

Sign in to watch

by Apache

CVEs (3)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2016-1000031Cri0.689.80.56Oct 25, 2016Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
CVE-2014-00500.030.93Apr 1, 2014MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
CVE-2013-02480.000.00Mar 15, 2013The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.