Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Xerces C\+\+ HIGH 7.5
CVE-2012-0880

Apache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes has…

Mitigation only
Fix from $1,950 2017-08-08
Commons Email HIGH 7.5
CVE-2017-9801EPSS 6%

When a call-site passes a subject for an email that contains line-breaks in Apache Commons Email 1.0 through 1.4, the caller can add arbitrary SMTP h…

Mitigation only
Fix from $1,950 2017-08-07
HTTP Server HIGH 7.5
CVE-2016-0736EPSS 49%

In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either C…

No fix yet
Fix from $1,950 2017-07-27
HTTP Server HIGH 7.5
CVE-2016-2161EPSS 21%

In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to cras…

Mitigation only
Fix from $1,950 2017-07-27
HTTP Server HIGH 7.5
CVE-2017-7659EPSS 54%

A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash the serve…

Mitigation only
Fix from $1,950 2017-07-26
Openmeetings HIGH 7.5
CVE-2017-7688

Apache OpenMeetings 1.0.0 updates user password in insecure manner.

No fix yet
Fix from $1,950 2017-07-17
Openmeetings MEDIUM 5.3
CVE-2017-7685

Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH.

Mitigation only
Fix from $1,600 2017-07-17
Openmeetings CRITICAL 10.0
CVE-2017-7664

Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.

Mitigation only
Fix from $2,300 2017-07-17
Openmeetings CRITICAL 9.8
CVE-2017-7673

Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms …

Mitigation only
Fix from $2,300 2017-07-17
Openmeetings HIGH 8.8
CVE-2017-7666

Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.

Mitigation only
Fix from $1,950 2017-07-17
Openmeetings HIGH 8.8
CVE-2017-7681

Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the …

Mitigation only
Fix from $1,950 2017-07-17
Openmeetings HIGH 8.2
CVE-2017-7682

Apache OpenMeetings 3.2.0 is vulnerable to parameter manipulation attacks, as a result attacker has access to restricted areas.

Mitigation only
Fix from $1,950 2017-07-17
Openmeetings HIGH 7.5
CVE-2017-7680

Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file. This allows for flash content to be loaded from untrusted domains.

Mitigation only
Fix from $1,950 2017-07-17
Openmeetings HIGH 7.5
CVE-2017-7683

Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure.

Mitigation only
Fix from $1,950 2017-07-17
Openmeetings HIGH 7.5
CVE-2017-7684

Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded. An attacker can cause a denial of service by uploading multiple large files…

Mitigation only
Fix from $1,950 2017-07-17
Openmeetings MEDIUM 6.1
CVE-2017-7663

Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0.

Mitigation only
Fix from $1,600 2017-07-17
Roller HIGH 7.2
CVE-2015-0249

The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary…

Mitigation only
Fix from $1,950 2017-07-17
HTTP Server HIGH 7.5
CVE-2017-9789EPSS 10%

When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, r…

Mitigation only
Fix from $1,950 2017-07-13
Struts HIGH 7.5
CVE-2017-9787EPSS 10%

When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts versio…

Mitigation only
Fix from $1,950 2017-07-13
Struts MEDIUM 5.9
CVE-2017-7672EPSS 9%

If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used t…

Mitigation only
Fix from $1,600 2017-07-13
Impala CRITICAL 9.8
CVE-2017-5640

It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to ski…

Mitigation only
Fix from $2,300 2017-07-10
Impala HIGH 7.5
CVE-2017-5652

During a routine security analysis, it was found that one of the ports in Apache Impala (incubating) 2.7.0 to 2.8.0 sent data in plaintext even when …

Mitigation only
Fix from $1,950 2017-07-10
Solr HIGH 7.5
CVE-2017-7660EPSS 6%

Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node…

Mitigation only
Fix from $1,950 2017-07-07
Ignite HIGH 7.5
CVE-2017-7686

Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality…

Mitigation only
Fix from $1,950 2017-06-28
HTTP Server CRITICAL 9.8
CVE-2017-3169EPSS 20%

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_con…

Mitigation only
Fix from $2,300 2017-06-20
Ws Xmlrpc MEDIUM 6.5
CVE-2016-5004EPSS 6%

The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource …

No fix yet
Fix from $1,600 2017-06-06
Tomcat HIGH 7.5
CVE-2017-5664EPSS 17%

The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is configured for the error that occ…

Mitigation only
Fix from $1,950 2017-06-06
Hadoop HIGH 7.5
CVE-2017-7669

In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. W…

Mitigation only
Fix from $1,950 2017-06-05
Hive HIGH 7.5
CVE-2016-3083

Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the server's …

Mitigation only
Fix from $1,950 2017-05-30
Knox MEDIUM 6.8
CVE-2017-5646

For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing …

Mitigation only
Fix from $1,600 2017-05-26