Skip to main content

Vendor/product archive

apache / netbeans CVEs

Beta · best-effort

4 CVEs tagged to apache / netbeans3 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2020-11986

Published Sep 9, 2020

To be able to analyze gradle projects, the build scripts need to be executed. Apache NetBeans follows this pattern. This causes the code of the build script to be invoked at load…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-17561

Published Mar 30, 2020

The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" version…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17560

Published Mar 30, 2020

The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates a…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-17191

Published Dec 31, 2018

Apache NetBeans (incubating) 9.0 NetBeans Proxy Auto-Configuration (PAC) interpretation is vulnerable for remote command execution (RCE). Using the nashorn script engine the envir…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1