Vulnerability index

Browse CVEs

130 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Geode MEDIUM 5.3
CVE-2017-9796

When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execut…

Fix: 1.3.0+
Fix from $1,600 2018-01-10
Sling Jcr Contentloader HIGH 7.5
CVE-2012-3353

The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the con…

Mitigation only
Fix from $1,950 2018-01-09
Sling Authentication Service HIGH 8.8
CVE-2017-15700

A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the…

Mitigation only
Fix from $1,950 2017-12-18
Openoffice MEDIUM 5.5
CVE-2017-3157

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from …

Fix: after 4.1.3
Fix from $1,600 2017-11-20
Wicket HIGH 7.5
CVE-2014-3526

Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors invo…

Fix: 1.5.12+
Fix from $1,950 2017-10-30
Geode MEDIUM 6.5
CVE-2017-9797

When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send m…

Fix: after 1.2.0
Fix from $1,600 2017-10-03
Wicket MEDIUM 5.3
CVE-2014-0043

In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular cla…

Mitigation only
Fix from $1,600 2017-10-03
Tomcat HIGH 7.5
CVE-2017-12616EPSS 71%

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs …

Mitigation only
Fix from $1,950 2017-09-19
Directory Ldap Api HIGH 7.5
CVE-2015-3250EPSS 5%

Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.

Fix: after 1.0.0
Fix from $1,950 2017-09-07
Hadoop CRITICAL 9.8
CVE-2016-3086

The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeM…

Mitigation only
Fix from $2,300 2017-09-05
Hadoop MEDIUM 5.5
CVE-2016-5001

This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A lo…

Fix: after 2.6.3
Fix from $1,600 2017-08-30
Atlas HIGH 7.5
CVE-2017-3154

Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.

Mitigation only
Fix from $1,950 2017-08-29
Myfaces HIGH 7.5
CVE-2011-4343EPSS 5%

Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL express…

Patch available
Fix from $1,950 2017-08-08
Openmeetings HIGH 7.5
CVE-2017-7683

Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure.

Mitigation only
Fix from $1,950 2017-07-17
HTTP Server CRITICAL 9.1
CVE-2017-9788EPSS 57%

In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or…

Fix: after 2.4.26
Fix from $2,300 2017-07-13
Ignite HIGH 7.5
CVE-2017-7686

Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality…

Mitigation only
Fix from $1,950 2017-06-28
Qpid Broker J HIGH 7.5
CVE-2016-8741EPSS 6%

The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices…

Mitigation only
Fix from $1,950 2017-05-15
Ambari MEDIUM 6.5
CVE-2017-5655

In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary file…

Mitigation only
Fix from $1,600 2017-05-15
Tomcat HIGH 7.5
CVE-2017-5647EPSS 17%

A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.…

Mitigation only
Fix from $1,950 2017-04-17
Geode HIGH 7.5
CVE-2017-5649

Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUST…

Fix: after 1.1.0
Fix from $1,950 2017-04-04
Ambari MEDIUM 5.5
CVE-2016-4976

Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive informat…

Mitigation only
Fix from $1,600 2017-03-29
Tomcat HIGH 7.5
CVE-2016-8747EPSS 7%

An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11Inpu…

Fix: 8.5.10+
Fix from $1,950 2017-03-14
Tika MEDIUM 5.3
CVE-2015-3271EPSS 7%

Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.

Mitigation only
Fix from $1,600 2016-12-15
Hadoop MEDIUM 6.2
CVE-2015-1776

Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk…

Mitigation only
Fix from $1,600 2016-04-19
Qpid Proton MEDIUM 6.5
CVE-2016-2166

The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 i…

Fix: after 0.12.0
Fix from $1,600 2016-04-12
Openmeetings HIGH 7.5
CVE-2016-2164EPSS 7%

The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the…

Fix: after 3.1.0
Fix from $1,950 2016-04-11
Openmeetings HIGH 7.5
CVE-2016-0783EPSS 7%

The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attacke…

Fix: after 3.1.0
Fix from $1,950 2016-04-11
Sling HIGH 7.5
CVE-2016-0956EPSS 46%

The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sen…

Patch available
Fix from $1,950 2016-02-10
Subversion MEDIUM 5.0
CVE-2015-3184EPSS 11%

mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous a…

Fix: after 7.2.1
Fix from $1,600 2015-08-12
Tomcat Connectors MEDIUM 5.0
CVE-2014-8111EPSS 7%

Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to acce…

Fix: after 1.2.40
Fix from $1,600 2015-04-21