Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Struts HIGH 7.5
CVE-2016-4433EPSS 10%

Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted …

Mitigation only
Fix from $1,950 2016-07-04
Struts HIGH 7.5
CVE-2016-4431EPSS 10%

Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging …

Mitigation only
Fix from $1,950 2016-07-04
Struts HIGH 8.8
CVE-2016-4430

Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attac…

Mitigation only
Fix from $1,950 2016-07-04
Ranger HIGH 7.2
CVE-2016-2174

SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQ…

Mitigation only
Fix from $1,950 2016-06-13
Cloudstack MEDIUM 6.5
CVE-2016-3085

Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabl…

No fix yet
Fix from $1,600 2016-06-10
Struts CRITICAL 9.8
CVE-2016-3087EPSS 81%

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to exec…

No fix yet
Fix from $2,300 2016-06-07
James Server HIGH 8.1
CVE-2015-7611EPSS 69%

Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified v…

No fix yet
Fix from $1,950 2016-06-07
Hadoop MEDIUM 6.2
CVE-2015-1776

Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk…

Mitigation only
Fix from $1,600 2016-04-19
Camel HIGH 8.1
CVE-2015-5348EPSS 6%

Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in C…

No fix yet
Fix from $1,950 2016-04-15
Struts MEDIUM 6.1
CVE-2016-2162EPSS 8%

Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to con…

Mitigation only
Fix from $1,600 2016-04-12
Ldap Studio HIGH 7.8
CVE-2015-5349

The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers …

Mitigation only
Fix from $1,950 2016-04-11
Ranger HIGH 8.8
CVE-2016-0735

Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishand…

Mitigation only
Fix from $1,950 2016-04-11
Activemq MEDIUM 6.1
CVE-2016-0734EPSS 9%

The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for rem…

Mitigation only
Fix from $1,600 2016-04-07
Tomcat HIGH 8.8
CVE-2016-0714EPSS 13%

The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles s…

Mitigation only
Fix from $1,950 2016-02-25
Tomcat HIGH 8.8
CVE-2015-5351EPSS 10%

The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions a…

No fix yet
Fix from $1,950 2016-02-25
Tomcat HIGH 8.1
CVE-2015-5346EPSS 11%

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are us…

No fix yet
Fix from $1,950 2016-02-25
Hive HIGH 8.3
CVE-2015-7521EPSS 6%

The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, …

No fix yet
Fix from $1,950 2016-01-29
Subversion HIGH 8.6
CVE-2015-5259EPSS 57%

Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute ar…

Mitigation only
Fix from $1,950 2016-01-08
Hadoop HIGH 8.4
CVE-2015-7430

The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 before 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to…

Mitigation only
Fix from $1,950 2016-01-02
Hbase HIGH 7.3
CVE-2015-1836EPSS 7%

Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and o…

Mitigation only
Fix from $1,950 2015-12-21
Hive HIGH 7.3
CVE-2015-1772EPSS 7%

The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.…

Mitigation only
Fix from $1,950 2015-12-21
Ambari MEDIUM 6.5
CVE-2015-3270

Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibl…

Mitigation only
Fix from $1,600 2015-11-02
Ambari MEDIUM 5.5
CVE-2015-1775

Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users…

Mitigation only
Fix from $1,600 2015-11-02
Activemq HIGH 7.5
CVE-2014-3612EPSS 7%

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote att…

Mitigation only
Fix from $1,950 2015-08-24
Activemq MEDIUM 5.0
CVE-2015-1830EPSS 84%

Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows …

No fix yet
Fix from $1,600 2015-08-19
Struts HIGH 7.5
CVE-2015-1831EPSS 6%

The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unsp…

Mitigation only
Fix from $1,950 2015-07-16
Subversion MEDIUM 5.0
CVE-2015-0248EPSS 12%

The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of …

Mitigation only
Fix from $1,600 2015-04-08
Subversion HIGH 7.8
CVE-2015-0202EPSS 8%

The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large numbe…

Mitigation only
Fix from $1,950 2015-04-08
Cassandra HIGH 7.5
CVE-2015-0225EPSS 7%

The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI in…

No fix yet
Fix from $1,950 2015-04-03
Tomcat MEDIUM 6.4
CVE-2014-0227EPSS 21%

java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not pr…

Mitigation only
Fix from $1,600 2015-02-16