Vulnerability index

Browse CVEs

258 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Traffic Server HIGH 7.5
CVE-2017-5659

Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding.

Fix: after 6.2.0
Fix from $1,950 2017-04-17
Tomcat HIGH 7.1
CVE-2016-6816EPSS 40%

The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP reque…

No fix yet
Fix from $1,950 2017-03-20
HTTP Server HIGH 7.5
CVE-2016-8740EPSS 79%

The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-…

Patch available
Fix from $1,950 2016-12-05
Tomcat HIGH 7.8
CVE-2016-1240EPSS 10%

The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and …

No fix yet
Fix from $1,950 2016-10-03
Amqp 0 X Jms Client HIGH 7.5
CVE-2016-4974EPSS 6%

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which …

Fix: after 6.0.3
Fix from $1,950 2016-07-13
Struts MEDIUM 5.3
CVE-2016-4465EPSS 10%

The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a n…

Mitigation only
Fix from $1,600 2016-07-04
Struts CRITICAL 9.8
CVE-2016-4438EPSS 17%

The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.

Mitigation only
Fix from $2,300 2016-07-04
Struts HIGH 7.5
CVE-2016-4433EPSS 10%

Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted …

Mitigation only
Fix from $1,950 2016-07-04
Struts HIGH 7.5
CVE-2016-4431EPSS 10%

Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging …

Mitigation only
Fix from $1,950 2016-07-04
Tomcat HIGH 7.5
CVE-2016-3092EPSS 36%

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.…

Fix: after 1.3.1
Fix from $1,950 2016-07-04
Struts HIGH 8.2
CVE-2016-1182EPSS 26%

ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to con…

Patch available
Fix from $1,950 2016-07-04
Struts HIGH 7.5
CVE-2015-0899EPSS 21%

The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modi…

Patch available
Fix from $1,950 2016-07-04
Struts MEDIUM 5.3
CVE-2016-3093EPSS 8%

Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to ca…

Fix: after 3.0.11
Fix from $1,600 2016-06-07
Struts CRITICAL 9.8
CVE-2016-3087EPSS 81%

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to exec…

No fix yet
Fix from $2,300 2016-06-07
Qpid Broker J MEDIUM 5.9
CVE-2016-3094EPSS 8%

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a…

Fix: after 6.0.2
Fix from $1,600 2016-06-01
Struts CRITICAL 9.8
CVE-2016-3082EPSS 19%

XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary …

Patch available
Fix from $2,300 2016-04-26
Struts HIGH 8.8
CVE-2016-0785EPSS 9%

Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL eva…

Fix: 2.3.20.3+
Fix from $1,950 2016-04-12
Ofbiz CRITICAL 9.8
CVE-2016-2170EPSS 13%

Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java o…

Fix: 12.04.06 / 13.07.03+
Fix from $2,300 2016-04-12
HTTP Server MEDIUM 5.0
CVE-2015-3183EPSS 73%

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attacke…

Fix: 2.2.31 / 2.4.16+
Fix from $1,600 2015-07-20
Jackrabbit MEDIUM 6.4
CVE-2015-1833EPSS 51%

XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before …

Fix: after 2.0.5
Fix from $1,600 2015-05-29
HTTP Server MEDIUM 5.0
CVE-2015-0228EPSS 19%

The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a de…

Fix: after 2.4.12
Fix from $1,600 2015-03-08
Tomcat MEDIUM 5.0
CVE-2014-0095EPSS 8%

java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread c…

Patch available
Fix from $1,600 2014-05-31
Commons Beanutils HIGH 7.5
CVE-2014-0114EPSS 96%

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commo…

Fix: after 1.9.1
Fix from $1,950 2014-04-30
Couchdb MEDIUM 5.0
CVE-2014-2668EPSS 22%

Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via the count parameter to /_uuids.

Fix: after 1.5.0
Fix from $1,600 2014-03-28
Cordova HIGH 7.5
CVE-2012-6637EPSS 9%

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote a…

Fix: after 3.3.0
Fix from $1,950 2014-03-03
Tomcat MEDIUM 5.8
CVE-2013-4286EPSS 17%

Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle c…

Mitigation only
Fix from $1,600 2014-02-26
Tomcat HIGH 7.5
CVE-2013-2185EPSS 7%

The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Re…

Fix: after 7.0.39
Fix from $1,950 2014-01-19
Sling MEDIUM 5.8
CVE-2013-4390

Open redirect vulnerability in the AbstractAuthenticationFormServlet in the Auth Core (org.apache.sling.auth.core) bundle before 1.1.4 in Apache Slin…

Fix: after 1.1.2
Fix from $1,600 2013-10-24
Xml Security For C\+\+ MEDIUM 5.8
CVE-2013-2155EPSS 6%

Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to ca…

Fix: after 1.7.0
Fix from $1,600 2013-08-20
Ofbiz HIGH 10.0
CVE-2013-2250EPSS 12%

Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute ar…

Patch available
Fix from $1,950 2013-08-15