Vulnerability index

Browse CVEs

46 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Hadoop HIGH 8.8
CVE-2021-33036

In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run ar…

Fix: 2.10.2 / 3.2.3+
Fix from $1,950 2022-06-15
Dolphinscheduler HIGH 8.8
CVE-2021-27644

In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data so…

Fix: 1.3.6+
Fix from $1,950 2021-11-01
Dolphinscheduler MEDIUM 6.5
CVE-2020-13922

Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API inter…

Mitigation only
Fix from $1,600 2021-01-11
Vcl HIGH 8.8
CVE-2013-0267

The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated user…

Fix: 2.3.2+
Fix from $1,950 2018-02-21
Couchdb HIGH 7.8
CVE-2016-8742

The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file p…

No fix yet
Fix from $1,950 2018-02-12
Openoffice HIGH 7.8
CVE-2016-6804

The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operation that a…

Fix: 4.1.3+
Fix from $1,950 2017-11-20
Cordova In App Browser CRITICAL 9.8
CVE-2014-0073EPSS 8%

The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-Ap…

Fix: after 2.9.0
Fix from $2,300 2017-10-30
Hadoop HIGH 8.8
CVE-2016-6811

In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.

Fix: after 2.7.3
Fix from $1,950 2017-04-11
Hadoop MEDIUM 6.5
CVE-2014-0229

Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshN…

Mitigation only
Fix from $1,600 2017-03-23
Storm CRITICAL 9.8
CVE-2015-3188EPSS 14%

The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.

No fix yet
Fix from $2,300 2017-01-13
Tomcat HIGH 7.8
CVE-2016-6325

The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig…

Mitigation only
Fix from $1,950 2016-10-13
Ranger MEDIUM 6.5
CVE-2015-5167

The Policy Admin Tool in Apache Ranger before 0.5.1 allows remote authenticated users to bypass intended access restrictions via the REST API.

Fix: after 0.5.0
Fix from $1,600 2016-04-12
Ranger HIGH 8.8
CVE-2016-0735

Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishand…

Mitigation only
Fix from $1,950 2016-04-11
Ranger HIGH 7.1
CVE-2015-0266

The Policy Admin Tool in Apache Ranger before 0.5.0 allows remote authenticated users to bypass intended access restrictions via direct access to mod…

Fix: after 0.4.0.
Fix from $1,950 2016-04-11
Jetspeed HIGH 7.5
CVE-2016-2171EPSS 43%

The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to …

Fix: after 2.3.0
Fix from $1,950 2016-04-11
Tomcat HIGH 8.8
CVE-2016-0714EPSS 13%

The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles s…

Mitigation only
Fix from $1,950 2016-02-25
Hadoop HIGH 8.4
CVE-2015-7430

The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 before 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to…

Mitigation only
Fix from $1,950 2016-01-02
Ambari MEDIUM 6.5
CVE-2015-3270

Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibl…

Mitigation only
Fix from $1,600 2015-11-02
Activemq HIGH 7.5
CVE-2014-3576EPSS 13%

The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of s…

Fix: after 5.10.0
Fix from $1,950 2015-08-14
Wss4j MEDIUM 5.0
CVE-2015-0227EPSS 8%

Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors …

Fix: after 1.6.16
Fix from $1,600 2015-02-12
Qpid MEDIUM 5.0
CVE-2015-0223EPSS 7%

Unspecified vulnerability in Apache Qpid 0.30 and earlier allows remote attackers to bypass access restrictions on qpidd via unknown vectors, related…

Fix: after 0.30
Fix from $1,600 2015-02-02
Struts MEDIUM 5.8
CVE-2014-0116EPSS 7%

CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass me…

Mitigation only
Fix from $1,600 2014-05-08
Struts HIGH 7.5
CVE-2014-0112EPSS 98%

ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "mani…

Fix: 2.3.16.2+
Fix from $1,950 2014-04-29
Struts HIGH 7.5
CVE-2014-0113EPSS 78%

CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method…

Fix: 2.3.16.2+
Fix from $1,950 2014-04-29
Xalan Java HIGH 7.5
CVE-2014-0107EPSS 14%

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is en…

Fix: after 2.7.1
Fix from $1,950 2014-04-15
Commons Fileupload HIGH 7.5
CVE-2014-0050EPSS 83%

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to c…

Fix: after 1.3
Fix from $1,950 2014-04-01
Camel HIGH 7.5
CVE-2014-0002EPSS 33%

The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other uns…

Fix: after 2.11.3
Fix from $1,950 2014-03-21
Camel HIGH 7.5
CVE-2014-0003EPSS 7%

The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbit…

Fix: after 2.11.3
Fix from $1,950 2014-03-21
Cordova HIGH 7.5
CVE-2014-1881EPSS 11%

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an ev…

Fix: after 3.3.0
Fix from $1,950 2014-03-03
Cordova HIGH 7.5
CVE-2014-1882EPSS 12%

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an ev…

Fix: after 3.3.0
Fix from $1,950 2014-03-03