Vulnerability index

Browse CVEs

46 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 8.8 CVE-2021-33036 In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run ar… Hadoop 2.10.2 / 3.2.3+ Fix from $1,9502022-06-15 HIGH 8.8 CVE-2021-27644 In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data so… Dolphinscheduler 1.3.6+ Fix from $1,9502021-11-01 MEDIUM 6.5 CVE-2020-13922 Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API inter… Dolphinscheduler Mitigation only Fix from $1,6002021-01-11 HIGH 8.8 CVE-2013-0267 The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated user… Vcl 2.3.2+ Fix from $1,9502018-02-21 HIGH 7.8 CVE-2016-8742 The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file p… Couchdb No fix yet Fix from $1,9502018-02-12 HIGH 7.8 CVE-2016-6804 The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operation that a… Openoffice 4.1.3+ Fix from $1,9502017-11-20 CRITICAL 9.8 CVE-2014-0073EPSS 8% The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-Ap… Cordova In App Browser after 2.9.0 Fix from $2,3002017-10-30 HIGH 8.8 CVE-2016-6811 In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Hadoop after 2.7.3 Fix from $1,9502017-04-11 MEDIUM 6.5 CVE-2014-0229 Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshN… Hadoop Mitigation only Fix from $1,6002017-03-23 CRITICAL 9.8 CVE-2015-3188EPSS 14% The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors. Storm No fix yet Fix from $2,3002017-01-13 HIGH 7.8 CVE-2016-6325 The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig… Tomcat Mitigation only Fix from $1,9502016-10-13 MEDIUM 6.5 CVE-2015-5167 The Policy Admin Tool in Apache Ranger before 0.5.1 allows remote authenticated users to bypass intended access restrictions via the REST API. Ranger after 0.5.0 Fix from $1,6002016-04-12 HIGH 8.8 CVE-2016-0735 Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishand… Ranger Mitigation only Fix from $1,9502016-04-11 HIGH 7.1 CVE-2015-0266 The Policy Admin Tool in Apache Ranger before 0.5.0 allows remote authenticated users to bypass intended access restrictions via direct access to mod… Ranger after 0.4.0. Fix from $1,9502016-04-11 HIGH 7.5 CVE-2016-2171EPSS 43% The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to … Jetspeed after 2.3.0 Fix from $1,9502016-04-11 HIGH 8.8 CVE-2016-0714EPSS 13% The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles s… Tomcat Mitigation only Fix from $1,9502016-02-25 HIGH 8.4 CVE-2015-7430 The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 before 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to… Hadoop Mitigation only Fix from $1,9502016-01-02 MEDIUM 6.5 CVE-2015-3270 Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibl… Ambari Mitigation only Fix from $1,6002015-11-02 HIGH 7.5 CVE-2014-3576EPSS 13% The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of s… Activemq after 5.10.0 Fix from $1,9502015-08-14 MEDIUM 5.0 CVE-2015-0227EPSS 8% Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors … Wss4j after 1.6.16 Fix from $1,6002015-02-12 MEDIUM 5.0 CVE-2015-0223EPSS 7% Unspecified vulnerability in Apache Qpid 0.30 and earlier allows remote attackers to bypass access restrictions on qpidd via unknown vectors, related… Qpid after 0.30 Fix from $1,6002015-02-02 MEDIUM 5.8 CVE-2014-0116EPSS 7% CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass me… Struts Mitigation only Fix from $1,6002014-05-08 HIGH 7.5 CVE-2014-0112EPSS 98% ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "mani… Struts 2.3.16.2+ Fix from $1,9502014-04-29 HIGH 7.5 CVE-2014-0113EPSS 78% CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method… Struts 2.3.16.2+ Fix from $1,9502014-04-29 HIGH 7.5 CVE-2014-0107EPSS 14% The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is en… Xalan Java after 2.7.1 Fix from $1,9502014-04-15 HIGH 7.5 CVE-2014-0050EPSS 83% MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to c… Commons Fileupload after 1.3 Fix from $1,9502014-04-01 HIGH 7.5 CVE-2014-0002EPSS 33% The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other uns… Camel after 2.11.3 Fix from $1,9502014-03-21 HIGH 7.5 CVE-2014-0003EPSS 7% The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbit… Camel after 2.11.3 Fix from $1,9502014-03-21 HIGH 7.5 CVE-2014-1881EPSS 11% Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an ev… Cordova after 3.3.0 Fix from $1,9502014-03-03 HIGH 7.5 CVE-2014-1882EPSS 12% Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an ev… Cordova after 3.3.0 Fix from $1,9502014-03-03