Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Impala CRITICAL 9.8
CVE-2017-5640

It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to ski…

Mitigation only
Fix from $2,300 2017-07-10
Struts CRITICAL 9.8
CVE-2017-9791 KEVEPSS 99%

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the Act…

Patch available
Fix from $2,300 2017-07-10
HTTP Server CRITICAL 9.8
CVE-2017-3167EPSS 20%

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication p…

Fix: 2.2.33 / 2.4.26+
Fix from $2,300 2017-06-20
HTTP Server CRITICAL 9.8
CVE-2017-3169EPSS 19%

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_con…

Mitigation only
Fix from $2,300 2017-06-20
HTTP Server CRITICAL 9.8
CVE-2017-7679EPSS 32%

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Typ…

Fix: 2.2.33 / 2.4.26+
Fix from $2,300 2017-06-20
Ranger CRITICAL 9.8
CVE-2017-7676

Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in u…

Fix: after 0.7.0
Fix from $2,300 2017-06-14
Log4j CRITICAL 9.8
CVE-2017-5645EPSS 90%

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a …

Fix: 2.8.2+
Fix from $2,300 2017-04-17
Tomcat CRITICAL 9.8
CVE-2017-5651EPSS 7%

In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processin…

Patch available
Fix from $2,300 2017-04-17
Tomcat CRITICAL 9.1
CVE-2017-5648EPSS 13%

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0…

Mitigation only
Fix from $2,300 2017-04-17
Tomcat Jk Connector CRITICAL 9.8
CVE-2016-6808EPSS 18%

Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.

Fix: 1.2.42+
Fix from $2,300 2017-04-12
Tomee CRITICAL 9.8
CVE-2016-0779EPSS 10%

The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted s…

Fix: after 1.7.3
Fix from $2,300 2017-04-11
Nutch CRITICAL 9.8
CVE-2016-6809EPSS 8%

Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to d…

Fix: after 1.13
Fix from $2,300 2017-04-06
Tomcat CRITICAL 9.8
CVE-2016-8735 KEVEPSS 90%

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M1…

Fix: 6.0.48 / 7.0.73+
Fix from $2,300 2017-04-06
Ambari CRITICAL 9.8
CVE-2017-5642

During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.

Mitigation only
Fix from $2,300 2017-04-03
Ambari CRITICAL 9.8
CVE-2014-3582

In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates fo…

Fix: after 2.2.2
Fix from $2,300 2017-03-29
Ambari CRITICAL 9.8
CVE-2016-6807

Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that …

Mitigation only
Fix from $2,300 2017-03-28
Camel CRITICAL 9.8
CVE-2016-8749EPSS 10%

Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.

No fix yet
Fix from $2,300 2017-03-28
Struts CRITICAL 9.8
CVE-2017-5638 KEVEPSS 100%

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message gene…

Fix: 2.3.32 / 2.5.10.1+
Fix from $2,300 2017-03-11
Camel CRITICAL 9.8
CVE-2017-3159EPSS 6%

Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to secur…

Fix: after 2.18.1
Fix from $2,300 2017-03-07
Storm CRITICAL 9.8
CVE-2015-3188EPSS 14%

The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.

No fix yet
Fix from $2,300 2017-01-13
Commons Fileupload CRITICAL 9.8
CVE-2016-1000031EPSS 32%

Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution

Fix: after 1.3.2
Fix from $2,300 2016-10-25
Derby CRITICAL 9.1
CVE-2015-1832EPSS 11%

XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows…

Mitigation only
Fix from $2,300 2016-10-03
Myfaces Trinidad CRITICAL 9.8
CVE-2016-5019EPSS 7%

CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow…

Fix: 1.0.13 / 1.2.15+
Fix from $2,300 2016-10-03
Struts CRITICAL 9.8
CVE-2016-4436EPSS 6%

Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up.

Mitigation only
Fix from $2,300 2016-10-03
Cxf Fediz CRITICAL 9.8
CVE-2016-4464

The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured…

Mitigation only
Fix from $2,300 2016-09-21
Struts CRITICAL 9.8
CVE-2016-4438EPSS 17%

The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.

Mitigation only
Fix from $2,300 2016-07-04
Struts CRITICAL 9.8
CVE-2016-3087EPSS 81%

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to exec…

No fix yet
Fix from $2,300 2016-06-07
Aurora CRITICAL 9.8
CVE-2016-4437 KEVEPSS 93%

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code…

Fix: 0.18.1 / 1.2.5+
Fix from $2,300 2016-06-07
Qpid Broker J CRITICAL 9.1
CVE-2016-4432EPSS 8%

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and cons…

Fix: 6.0.3+
Fix from $2,300 2016-06-01
Activemq CRITICAL 9.8
CVE-2016-3088 KEVEPSS 99%

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT fol…

Fix: 5.14.0+
Fix from $2,300 2016-06-01