CVE-2023-52070

JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jfree:jfreechart:1.5.4:*:*:*:*:*:*:*

History

27 May 2025, 14:20

Type Values Removed Values Added
First Time Jfree
Jfree jfreechart
CPE cpe:2.3:a:jfree:jfreechart:1.5.4:*:*:*:*:*:*:*
References () http://jfreechart.com - () http://jfreechart.com - Broken Link
References () http://jfreeorg.com - () http://jfreeorg.com - Broken Link
References () https://gist.github.com/LLM4IG/f55de46e65fb5a19b7815adb36fd858b - () https://gist.github.com/LLM4IG/f55de46e65fb5a19b7815adb36fd858b - Third Party Advisory

21 Nov 2024, 08:39

Type Values Removed Values Added
References () http://jfreechart.com - () http://jfreechart.com -
References () http://jfreeorg.com - () http://jfreeorg.com -
References () https://gist.github.com/LLM4IG/f55de46e65fb5a19b7815adb36fd858b - () https://gist.github.com/LLM4IG/f55de46e65fb5a19b7815adb36fd858b -

16 Aug 2024, 15:35

Type Values Removed Values Added
CWE CWE-125
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.4

11 Apr 2024, 19:15

Type Values Removed Values Added
Summary JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method. JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

10 Apr 2024, 19:49

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-10 19:15

Updated : 2025-05-27 14:20


NVD link : CVE-2023-52070

Mitre link : CVE-2023-52070

CVE.ORG link : CVE-2023-52070


JSON object : View

Products Affected

jfree

  • jfreechart
CWE
CWE-125

Out-of-bounds Read