Vulnerability index

Browse CVEs

39 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Activemq HIGH 7.4
CVE-2018-11775EPSS 7%

TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack bet…

Fix: 5.15.6+
Fix from $1,950 2018-09-10
Tomcat HIGH 7.5
CVE-2018-8034EPSS 21%

The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0…

Fix: after 9.0.9
Fix from $1,950 2018-08-01
Tomcat Native MEDIUM 5.9
CVE-2017-15698

When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly h…

Fix: after 1.2.14
Fix from $1,600 2018-01-31
Hive HIGH 7.5
CVE-2016-3083

Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the server's …

Mitigation only
Fix from $1,950 2017-05-30
Qpid Proton MEDIUM 5.9
CVE-2016-4467

The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname m…

Mitigation only
Fix from $1,600 2017-05-02
Cxf MEDIUM 5.3
CVE-2017-5653EPSS 11%

JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which…

Fix: after 3.1.11
Fix from $1,600 2017-04-18
Libcloud MEDIUM 5.9
CVE-2012-3446

Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the su…

Fix: 0.11.0+
Fix from $1,600 2012-11-04
Httpclient MEDIUM 5.8
CVE-2012-5783EPSS 9%

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the serve…

Patch available
Fix from $1,600 2012-11-04
HTTP Server CRITICAL 9.8
CVE-2009-3555EPSS 87%

The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache …

Fix: after 3.12.4
Fix from $2,300 2009-11-09