Skip to main content

Vendor/product archive

apache / batik CVEs

Beta · best-effort

11 CVEs tagged to apache / batik1 Critical, 6 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2022-42890

Published Oct 25, 2022

A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41704

Published Oct 25, 2022

A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40146

Published Sep 22, 2022

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-38648

Published Sep 22, 2022

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38398

Published Sep 22, 2022

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Bat…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5662

Published Apr 18, 2017

In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types t…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0508

Published Mar 14, 2005

Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a "script sec…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1