Vulnerability index

Browse CVEs

46 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Cordova HIGH 7.5
CVE-2014-1884EPSS 8%

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier on Windows Phone 7 and 8 do not properly restrict navigation events, which allo…

Fix: after 3.3.0
Fix from $1,950 2014-03-03
Struts MEDIUM 5.8
CVE-2013-4310EPSS 7%

Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.

Patch available
Fix from $1,600 2013-09-30
Openjpa HIGH 7.5
CVE-2013-1768EPSS 10%

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace d…

Mitigation only
Fix from $1,950 2013-07-11
Tomcat MEDIUM 5.0
CVE-2012-5885EPSS 9%

The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.…

Mitigation only
Fix from $1,600 2012-11-17
Cloudstack HIGH 10.0
CVE-2012-4501EPSS 8%

Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user acc…

Mitigation only
Fix from $1,950 2012-10-26
Struts MEDIUM 5.0
CVE-2012-4387EPSS 8%

Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processe…

Patch available
Fix from $1,600 2012-09-05
Org.apache.sling.servlets.post MEDIUM 5.0
CVE-2012-2138EPSS 14%

The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to co…

Fix: after 2.1.0
Fix from $1,600 2012-07-09
Tomcat MEDIUM 5.0
CVE-2011-1184EPSS 9%

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the…

Patch available
Fix from $1,600 2012-01-14
Tomcat MEDIUM 5.0
CVE-2011-5062EPSS 8%

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qo…

Patch available
Fix from $1,600 2012-01-14
Struts MEDIUM 5.0
CVE-2011-5057EPSS 29%

Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and req…

Fix: 2.3.3+
Fix from $1,600 2012-01-08
Struts MEDIUM 6.4
CVE-2012-0393EPSS 37%

The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to c…

Fix: 2.3.1.1+
Fix from $1,600 2012-01-08
Tomcat HIGH 7.5
CVE-2011-3190EPSS 15%

Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other …

No fix yet
Fix from $1,950 2011-08-31
Tomcat MEDIUM 5.0
CVE-2011-2729EPSS 7%

native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33,…

Patch available
Fix from $1,600 2011-08-15
Rampart\/c MEDIUM 6.5
CVE-2011-2329

The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 does not properly calculate the expiration …

Patch available
Fix from $1,600 2011-06-02
Apache Webserver MEDIUM 6.5
CVE-2008-2717

TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which al…

Mitigation only
Fix from $1,600 2008-06-16
Tomcat MEDIUM 6.4
CVE-2007-5342EPSS 5%

The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain pe…

Patch available
Fix from $1,600 2007-12-27