Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Couchdb CRITICAL 9.8
CVE-2017-12635EPSS 100%

Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1…

Fix: 1.7.0+
Fix from $2,300 2017-11-14
Hadoop CRITICAL 9.8
CVE-2012-4449

Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features ar…

Fix: after 0.23.3
Fix from $2,300 2017-10-30
Httpclient CRITICAL 9.8
CVE-2013-4366

http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows a…

Patch available
Fix from $2,300 2017-10-30
Cordova In App Browser CRITICAL 9.8
CVE-2014-0073EPSS 8%

The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-Ap…

Fix: after 2.9.0
Fix from $2,300 2017-10-30
Traffic Server CRITICAL 9.8
CVE-2014-3624

Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap request…

Patch available
Fix from $2,300 2017-10-30
Traffic Server CRITICAL 9.8
CVE-2015-3249EPSS 5%

The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds acces…

Mitigation only
Fix from $2,300 2017-10-30
Activemq Apollo CRITICAL 9.8
CVE-2014-3579

XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors inv…

Mitigation only
Fix from $2,300 2017-10-27
Activemq CRITICAL 9.8
CVE-2014-3600EPSS 9%

XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving…

Mitigation only
Fix from $2,300 2017-10-27
Ws Xmlrpc CRITICAL 9.8
CVE-2016-5003EPSS 15%

The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serializ…

No fix yet
Fix from $2,300 2017-10-27
Ofbiz CRITICAL 9.8
CVE-2012-1622EPSS 5%

Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.

Mitigation only
Fix from $2,300 2017-10-26
Nifi CRITICAL 9.8
CVE-2017-5636

In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injectio…

Mitigation only
Fix from $2,300 2017-10-19
Solr CRITICAL 9.8
CVE-2017-12629EPSS 92%

Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-li…

Fix: after 7.0.1
Fix from $2,300 2017-10-14
Openmeetings CRITICAL 9.8
CVE-2016-8736

Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.

Fix: 3.1.2+
Fix from $2,300 2017-10-12
Roller CRITICAL 9.8
CVE-2014-0030EPSS 15%

The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.

No fix yet
Fix from $2,300 2017-10-10
Opennlp CRITICAL 9.8
CVE-2017-12620

When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects ap…

No fix yet
Fix from $2,300 2017-10-03
Commons Jelly CRITICAL 9.8
CVE-2017-12621EPSS 9%

During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used …

Fix: 1.0.1+
Fix from $2,300 2017-09-28
Struts CRITICAL 9.8
CVE-2016-6795EPSS 8%

In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for…

Mitigation only
Fix from $2,300 2017-09-20
Struts CRITICAL 9.8
CVE-2017-12611EPSS 95%

In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can …

Patch available
Fix from $2,300 2017-09-20
Traffic Server CRITICAL 9.8
CVE-2015-5168

Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a dif…

No fix yet
Fix from $2,300 2017-09-13
Traffic Server CRITICAL 9.8
CVE-2015-5206

Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unknown impact and attack vectors…

Mitigation only
Fix from $2,300 2017-09-13
Hadoop CRITICAL 9.8
CVE-2016-3086

The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeM…

Mitigation only
Fix from $2,300 2017-09-05
Pony Mail CRITICAL 9.8
CVE-2016-4460EPSS 5%

Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.

Patch available
Fix from $2,300 2017-08-22
Subversion CRITICAL 9.8
CVE-2017-9800EPSS 18%

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run …

Fix: after 1.8.18
Fix from $2,300 2017-08-11
Tomcat CRITICAL 9.1
CVE-2016-5018EPSS 10%

In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able …

Fix: after 8.5.4
Fix from $2,300 2017-08-10
Cxf CRITICAL 9.8
CVE-2012-0803

The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as pa…

Patch available
Fix from $2,300 2017-08-08
Sling CRITICAL 9.8
CVE-2016-6798

In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string…

Fix: after 1.0.10
Fix from $2,300 2017-07-19
Openmeetings CRITICAL 10.0
CVE-2017-7664

Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.

Mitigation only
Fix from $2,300 2017-07-17
Openmeetings CRITICAL 9.8
CVE-2017-7673

Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms …

Mitigation only
Fix from $2,300 2017-07-17
Wicket CRITICAL 9.1
CVE-2016-6793EPSS 9%

The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop…

Fix: 1.5.17 / 6.25.0+
Fix from $2,300 2017-07-17
HTTP Server CRITICAL 9.1
CVE-2017-9788EPSS 54%

In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or…

Fix: after 2.4.26
Fix from $2,300 2017-07-13