Vulnerability index

Browse CVEs

258 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Vcl HIGH 8.8
CVE-2013-0267

The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated user…

Fix: 2.3.2+
Fix from $1,950 2018-02-21
Qpid Dispatch MEDIUM 6.5
CVE-2017-15699

A Denial of Service vulnerability was found in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0. To exploit this vulnerability, a remote user mus…

Patch available
Fix from $1,600 2018-02-13
Qpid Broker J MEDIUM 5.9
CVE-2018-1298

A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocols 0-8, …

Mitigation only
Fix from $1,600 2018-02-09
Nifi CRITICAL 9.8
CVE-2017-15697

A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fi…

Fix: after 1.4.0
Fix from $2,300 2018-01-23
Nifi HIGH 7.5
CVE-2017-12632

A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and …

Fix: after 1.4.0
Fix from $1,950 2018-01-23
Struts MEDIUM 6.2
CVE-2017-15707

In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malici…

Fix: after 2.5.14
Fix from $1,600 2017-12-01
Karaf MEDIUM 5.5
CVE-2014-0219

Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sen…

Fix: 4.0.10+
Fix from $1,600 2017-11-15
Httpclient CRITICAL 9.8
CVE-2013-4366

http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows a…

Patch available
Fix from $2,300 2017-10-30
Cordova File Transfer HIGH 7.5
CVE-2014-0072EPSS 8%

ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.4.2 for iOS and the File-Tran…

Fix: after 2.9.0
Fix from $1,950 2017-10-30
Juddi MEDIUM 5.3
CVE-2009-1197

Apache jUDDI before 2.0 allows attackers to spoof entries in log files via vectors related to error logging of keys from uddiget.jsp.

Mitigation only
Fix from $1,600 2017-10-30
Struts HIGH 8.8
CVE-2016-3090EPSS 6%

The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL e…

Mitigation only
Fix from $1,950 2017-10-30
Cordova MEDIUM 5.3
CVE-2015-1835EPSS 6%

Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to …

Fix: after 3.7.1
Fix from $1,600 2017-10-27
Struts HIGH 8.8
CVE-2016-4461EPSS 8%

Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL eva…

Fix: 2.3.29+
Fix from $1,950 2017-10-16
Struts CRITICAL 9.8
CVE-2017-12611EPSS 87%

In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can …

Patch available
Fix from $2,300 2017-09-20
Struts HIGH 7.5
CVE-2017-9793EPSS 9%

The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allo…

Patch available
Fix from $1,950 2017-09-20
Struts HIGH 7.5
CVE-2017-9804EPSS 8%

In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is us…

Patch available
Fix from $1,950 2017-09-20
Struts MEDIUM 5.9
CVE-2016-8738

In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to …

Patch available
Fix from $1,600 2017-09-20
Ofbiz HIGH 8.8
CVE-2016-4462

By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that ar…

Mitigation only
Fix from $1,950 2017-08-30
Struts HIGH 7.5
CVE-2015-5209EPSS 9%

Apache Struts 2.x before 2.3.24.1 allows remote attackers to manipulate Struts internals, alter user sessions, or affect container settings via vecto…

Mitigation only
Fix from $1,950 2017-08-29
Subversion CRITICAL 9.8
CVE-2017-9800EPSS 19%

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run …

Fix: after 1.8.18
Fix from $2,300 2017-08-11
Commons Email HIGH 7.5
CVE-2017-9801EPSS 6%

When a call-site passes a subject for an email that contains line-breaks in Apache Commons Email 1.0 through 1.4, the caller can add arbitrary SMTP h…

Mitigation only
Fix from $1,950 2017-08-07
HTTP Server HIGH 7.5
CVE-2016-2161EPSS 21%

In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to cras…

Mitigation only
Fix from $1,950 2017-07-27
HTTP Server CRITICAL 9.1
CVE-2017-9788EPSS 57%

In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or…

Fix: after 2.4.26
Fix from $2,300 2017-07-13
Struts MEDIUM 5.9
CVE-2017-7672EPSS 9%

If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used t…

Mitigation only
Fix from $1,600 2017-07-13
Struts CRITICAL 9.8
CVE-2017-9791 KEVEPSS 99%

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the Act…

Patch available
Fix from $2,300 2017-07-10
Thrift MEDIUM 6.5
CVE-2015-3254EPSS 5%

The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vecto…

Fix: after 0.9.2
Fix from $1,600 2017-06-16
Ranger CRITICAL 9.8
CVE-2017-7676

Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in u…

Fix: after 0.7.0
Fix from $2,300 2017-06-14
Cxf Fediz HIGH 7.5
CVE-2015-5175EPSS 11%

Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service.

Fix: after 1.1.2
Fix from $1,950 2017-06-07
Hadoop HIGH 7.5
CVE-2017-7669

In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. W…

Mitigation only
Fix from $1,950 2017-06-05
Hadoop HIGH 7.3
CVE-2017-3162EPSS 6%

HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query parameter that is not validate…

Fix: after 2.6.5
Fix from $1,950 2017-04-26