Vulnerability index

Browse CVEs

130 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2017-9796 When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execut… Geode 1.3.0+ Fix from $1,6002018-01-10 HIGH 7.5 CVE-2012-3353 The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the con… Sling Jcr Contentloader Mitigation only Fix from $1,9502018-01-09 HIGH 8.8 CVE-2017-15700 A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the… Sling Authentication Service Mitigation only Fix from $1,9502017-12-18 MEDIUM 5.5 CVE-2017-3157 By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from … Openoffice after 4.1.3 Fix from $1,6002017-11-20 HIGH 7.5 CVE-2014-3526 Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors invo… Wicket 1.5.12+ Fix from $1,9502017-10-30 MEDIUM 6.5 CVE-2017-9797 When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send m… Geode after 1.2.0 Fix from $1,6002017-10-03 MEDIUM 5.3 CVE-2014-0043 In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular cla… Wicket Mitigation only Fix from $1,6002017-10-03 HIGH 7.5 CVE-2017-12616EPSS 71% When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs … Tomcat Mitigation only Fix from $1,9502017-09-19 HIGH 7.5 CVE-2015-3250EPSS 5% Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors. Directory Ldap Api after 1.0.0 Fix from $1,9502017-09-07 CRITICAL 9.8 CVE-2016-3086 The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeM… Hadoop Mitigation only Fix from $2,3002017-09-05 MEDIUM 5.5 CVE-2016-5001 This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A lo… Hadoop after 2.6.3 Fix from $1,6002017-08-30 HIGH 7.5 CVE-2017-3154 Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information. Atlas Mitigation only Fix from $1,9502017-08-29 HIGH 7.5 CVE-2011-4343EPSS 5% Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL express… Myfaces Patch available Fix from $1,9502017-08-08 HIGH 7.5 CVE-2017-7683 Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure. Openmeetings Mitigation only Fix from $1,9502017-07-17 CRITICAL 9.1 CVE-2017-9788EPSS 57% In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or… HTTP Server after 2.4.26 Fix from $2,3002017-07-13 HIGH 7.5 CVE-2017-7686 Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality… Ignite Mitigation only Fix from $1,9502017-06-28 HIGH 7.5 CVE-2016-8741EPSS 6% The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices… Qpid Broker J Mitigation only Fix from $1,9502017-05-15 MEDIUM 6.5 CVE-2017-5655 In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary file… Ambari Mitigation only Fix from $1,6002017-05-15 HIGH 7.5 CVE-2017-5647EPSS 17% A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.… Tomcat Mitigation only Fix from $1,9502017-04-17 HIGH 7.5 CVE-2017-5649 Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUST… Geode after 1.1.0 Fix from $1,9502017-04-04 MEDIUM 5.5 CVE-2016-4976 Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive informat… Ambari Mitigation only Fix from $1,6002017-03-29 HIGH 7.5 CVE-2016-8747EPSS 7% An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11Inpu… Tomcat 8.5.10+ Fix from $1,9502017-03-14 MEDIUM 5.3 CVE-2015-3271EPSS 7% Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header. Tika Mitigation only Fix from $1,6002016-12-15 MEDIUM 6.2 CVE-2015-1776 Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk… Hadoop Mitigation only Fix from $1,6002016-04-19 MEDIUM 6.5 CVE-2016-2166 The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 i… Qpid Proton after 0.12.0 Fix from $1,6002016-04-12 HIGH 7.5 CVE-2016-2164EPSS 7% The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the… Openmeetings after 3.1.0 Fix from $1,9502016-04-11 HIGH 7.5 CVE-2016-0783EPSS 7% The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attacke… Openmeetings after 3.1.0 Fix from $1,9502016-04-11 HIGH 7.5 CVE-2016-0956EPSS 46% The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sen… Sling Patch available Fix from $1,9502016-02-10 MEDIUM 5.0 CVE-2015-3184EPSS 11% mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous a… Subversion after 7.2.1 Fix from $1,6002015-08-12 MEDIUM 5.0 CVE-2014-8111EPSS 7% Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to acce… Tomcat Connectors after 1.2.40 Fix from $1,6002015-04-21