Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Santuario Xml Security For Java MEDIUM 5.0
CVE-2014-8152EPSS 6%

Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a cr…

Mitigation only
Fix from $1,600 2015-01-21
HTTP Server MEDIUM 5.0
CVE-2014-3583EPSS 11%

The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause …

Mitigation only
Fix from $1,600 2014-12-15
Struts MEDIUM 6.8
CVE-2014-7809

Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mecha…

No fix yet
Fix from $1,600 2014-12-10
Cloudstack MEDIUM 5.0
CVE-2014-7807

Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, …

Mitigation only
Fix from $1,600 2014-12-10
Hadoop MEDIUM 5.0
CVE-2014-3627

The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster u…

Mitigation only
Fix from $1,600 2014-12-05
Shiro HIGH 7.5
CVE-2014-0074EPSS 5%

Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an e…

No fix yet
Fix from $1,950 2014-10-06
Traffic Server HIGH 10.0
CVE-2014-3525

Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors,…

No fix yet
Fix from $1,950 2014-08-22
Syncope MEDIUM 5.0
CVE-2014-3503EPSS 6%

Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via…

No fix yet
Fix from $1,600 2014-07-11
Tomcat MEDIUM 5.0
CVE-2014-0075EPSS 20%

Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6.0.40, 7.…

Mitigation only
Fix from $1,600 2014-05-31
Struts MEDIUM 5.8
CVE-2014-0116EPSS 7%

CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass me…

Mitigation only
Fix from $1,600 2014-05-08
Tomcat MEDIUM 5.8
CVE-2013-4286EPSS 17%

Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle c…

Mitigation only
Fix from $1,600 2014-02-26
Wicket MEDIUM 5.0
CVE-2013-2055

Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive…

Mitigation only
Fix from $1,600 2014-02-10
Cxf MEDIUM 6.4
CVE-2012-5575EPSS 6%

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowe…

Mitigation only
Fix from $1,600 2013-08-19
Struts MEDIUM 5.8
CVE-2013-2248EPSS 95%

Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and cond…

Mitigation only
Fix from $1,600 2013-07-20
Openjpa HIGH 7.5
CVE-2013-1768EPSS 10%

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace d…

Mitigation only
Fix from $1,950 2013-07-11
Subversion MEDIUM 5.0
CVE-2013-1847EPSS 51%

The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,600 2013-05-02
Subversion MEDIUM 5.0
CVE-2013-1884EPSS 51%

The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault…

Mitigation only
Fix from $1,600 2013-05-02
Tomcat MEDIUM 5.0
CVE-2012-5885EPSS 9%

The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.…

Mitigation only
Fix from $1,600 2012-11-17
Tomcat MEDIUM 5.0
CVE-2012-5886EPSS 9%

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches informatio…

Mitigation only
Fix from $1,600 2012-11-17
Tomcat MEDIUM 5.0
CVE-2012-2733EPSS 9%

java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not…

Mitigation only
Fix from $1,600 2012-11-16
Cloudstack HIGH 10.0
CVE-2012-4501EPSS 8%

Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user acc…

Mitigation only
Fix from $1,950 2012-10-26
Axis2 MEDIUM 6.4
CVE-2012-5351EPSS 5%

Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signatur…

Mitigation only
Fix from $1,600 2012-10-09
Axis2 MEDIUM 5.8
CVE-2012-4418EPSS 6%

Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."

No fix yet
Fix from $1,600 2012-10-09
Struts MEDIUM 6.8
CVE-2012-4386

The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote…

Mitigation only
Fix from $1,600 2012-09-05
Hadoop HIGH 7.5
CVE-2012-3376

DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same B…

Mitigation only
Fix from $1,950 2012-07-12
Qpid HIGH 7.5
CVE-2011-3620EPSS 5%

Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messagin…

Mitigation only
Fix from $1,950 2012-05-03
Hadoop MEDIUM 6.5
CVE-2012-1574

The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used i…

Mitigation only
Fix from $1,600 2012-04-12
Wicket MEDIUM 5.0
CVE-2012-1089EPSS 5%

Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-applicati…

Mitigation only
Fix from $1,600 2012-03-23
Tomcat MEDIUM 5.0
CVE-2011-3375EPSS 7%

Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request object…

Mitigation only
Fix from $1,600 2012-01-19
Tomcat MEDIUM 5.0
CVE-2012-0022EPSS 11%

Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote…

Mitigation only
Fix from $1,600 2012-01-19