Vulnerability index

Browse CVEs

583 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2017-12635EPSS 100% Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1… Couchdb 1.7.0+ Fix from $2,3002017-11-14 CRITICAL 9.8 CVE-2012-4449 Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features ar… Hadoop after 0.23.3 Fix from $2,3002017-10-30 CRITICAL 9.8 CVE-2013-4366 http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows a… Httpclient Patch available Fix from $2,3002017-10-30 CRITICAL 9.8 CVE-2014-0073EPSS 8% The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-Ap… Cordova In App Browser after 2.9.0 Fix from $2,3002017-10-30 CRITICAL 9.8 CVE-2014-3624 Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap request… Traffic Server Patch available Fix from $2,3002017-10-30 CRITICAL 9.8 CVE-2015-3249EPSS 5% The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds acces… Traffic Server Mitigation only Fix from $2,3002017-10-30 CRITICAL 9.8 CVE-2014-3579 XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors inv… Activemq Apollo Mitigation only Fix from $2,3002017-10-27 CRITICAL 9.8 CVE-2014-3600EPSS 9% XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving… Activemq Mitigation only Fix from $2,3002017-10-27 CRITICAL 9.8 CVE-2016-5003EPSS 15% The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serializ… Ws Xmlrpc No fix yet Fix from $2,3002017-10-27 CRITICAL 9.8 CVE-2012-1622EPSS 5% Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors. Ofbiz Mitigation only Fix from $2,3002017-10-26 CRITICAL 9.8 CVE-2017-5636 In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injectio… Nifi Mitigation only Fix from $2,3002017-10-19 CRITICAL 9.8 CVE-2017-12629EPSS 92% Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-li… Solr after 7.0.1 Fix from $2,3002017-10-14 CRITICAL 9.8 CVE-2016-8736 Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack. Openmeetings 3.1.2+ Fix from $2,3002017-10-12 CRITICAL 9.8 CVE-2014-0030EPSS 15% The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors. Roller No fix yet Fix from $2,3002017-10-10 CRITICAL 9.8 CVE-2017-12620 When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects ap… Opennlp No fix yet Fix from $2,3002017-10-03 CRITICAL 9.8 CVE-2017-12621EPSS 9% During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used … Commons Jelly 1.0.1+ Fix from $2,3002017-09-28 CRITICAL 9.8 CVE-2016-6795EPSS 8% In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for… Struts Mitigation only Fix from $2,3002017-09-20 CRITICAL 9.8 CVE-2017-12611EPSS 95% In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can … Struts Patch available Fix from $2,3002017-09-20 CRITICAL 9.8 CVE-2015-5168 Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a dif… Traffic Server No fix yet Fix from $2,3002017-09-13 CRITICAL 9.8 CVE-2015-5206 Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unknown impact and attack vectors… Traffic Server Mitigation only Fix from $2,3002017-09-13 CRITICAL 9.8 CVE-2016-3086 The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeM… Hadoop Mitigation only Fix from $2,3002017-09-05 CRITICAL 9.8 CVE-2016-4460EPSS 5% Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication. Pony Mail Patch available Fix from $2,3002017-08-22 CRITICAL 9.8 CVE-2017-9800EPSS 18% A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run … Subversion after 1.8.18 Fix from $2,3002017-08-11 CRITICAL 9.1 CVE-2016-5018EPSS 10% In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able … Tomcat after 8.5.4 Fix from $2,3002017-08-10 CRITICAL 9.8 CVE-2012-0803 The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as pa… Cxf Patch available Fix from $2,3002017-08-08 CRITICAL 9.8 CVE-2016-6798 In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string… Sling after 1.0.10 Fix from $2,3002017-07-19 CRITICAL 10.0 CVE-2017-7664 Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0. Openmeetings Mitigation only Fix from $2,3002017-07-17 CRITICAL 9.8 CVE-2017-7673 Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms … Openmeetings Mitigation only Fix from $2,3002017-07-17 CRITICAL 9.1 CVE-2016-6793EPSS 9% The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop… Wicket 1.5.17 / 6.25.0+ Fix from $2,3002017-07-17 CRITICAL 9.1 CVE-2017-9788EPSS 54% In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or… HTTP Server after 2.4.26 Fix from $2,3002017-07-13