Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2016-4433EPSS 10% Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted … Struts Mitigation only Fix from $1,9502016-07-04 HIGH 7.5 CVE-2016-4431EPSS 10% Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging … Struts Mitigation only Fix from $1,9502016-07-04 HIGH 8.8 CVE-2016-4430 Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attac… Struts Mitigation only Fix from $1,9502016-07-04 HIGH 7.2 CVE-2016-2174 SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQ… Ranger Mitigation only Fix from $1,9502016-06-13 MEDIUM 6.5 CVE-2016-3085 Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabl… Cloudstack No fix yet Fix from $1,6002016-06-10 CRITICAL 9.8 CVE-2016-3087EPSS 81% Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to exec… Struts No fix yet Fix from $2,3002016-06-07 HIGH 8.1 CVE-2015-7611EPSS 69% Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified v… James Server No fix yet Fix from $1,9502016-06-07 MEDIUM 6.2 CVE-2015-1776 Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk… Hadoop Mitigation only Fix from $1,6002016-04-19 HIGH 8.1 CVE-2015-5348EPSS 6% Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in C… Camel No fix yet Fix from $1,9502016-04-15 MEDIUM 6.1 CVE-2016-2162EPSS 8% Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to con… Struts Mitigation only Fix from $1,6002016-04-12 HIGH 7.8 CVE-2015-5349 The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers … Ldap Studio Mitigation only Fix from $1,9502016-04-11 HIGH 8.8 CVE-2016-0735 Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishand… Ranger Mitigation only Fix from $1,9502016-04-11 MEDIUM 6.1 CVE-2016-0734EPSS 9% The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for rem… Activemq Mitigation only Fix from $1,6002016-04-07 HIGH 8.8 CVE-2016-0714EPSS 13% The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles s… Tomcat Mitigation only Fix from $1,9502016-02-25 HIGH 8.8 CVE-2015-5351EPSS 10% The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions a… Tomcat No fix yet Fix from $1,9502016-02-25 HIGH 8.1 CVE-2015-5346EPSS 11% Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are us… Tomcat No fix yet Fix from $1,9502016-02-25 HIGH 8.3 CVE-2015-7521EPSS 6% The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, … Hive No fix yet Fix from $1,9502016-01-29 HIGH 8.6 CVE-2015-5259EPSS 57% Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute ar… Subversion Mitigation only Fix from $1,9502016-01-08 HIGH 8.4 CVE-2015-7430 The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 before 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to… Hadoop Mitigation only Fix from $1,9502016-01-02 HIGH 7.3 CVE-2015-1836EPSS 7% Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and o… Hbase Mitigation only Fix from $1,9502015-12-21 HIGH 7.3 CVE-2015-1772EPSS 7% The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.… Hive Mitigation only Fix from $1,9502015-12-21 MEDIUM 6.5 CVE-2015-3270 Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibl… Ambari Mitigation only Fix from $1,6002015-11-02 MEDIUM 5.5 CVE-2015-1775 Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users… Ambari Mitigation only Fix from $1,6002015-11-02 HIGH 7.5 CVE-2014-3612EPSS 7% The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote att… Activemq Mitigation only Fix from $1,9502015-08-24 MEDIUM 5.0 CVE-2015-1830EPSS 84% Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows … Activemq No fix yet Fix from $1,6002015-08-19 HIGH 7.5 CVE-2015-1831EPSS 6% The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unsp… Struts Mitigation only Fix from $1,9502015-07-16 MEDIUM 5.0 CVE-2015-0248EPSS 12% The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of … Subversion Mitigation only Fix from $1,6002015-04-08 HIGH 7.8 CVE-2015-0202EPSS 8% The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large numbe… Subversion Mitigation only Fix from $1,9502015-04-08 HIGH 7.5 CVE-2015-0225EPSS 7% The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI in… Cassandra No fix yet Fix from $1,9502015-04-03 MEDIUM 6.4 CVE-2014-0227EPSS 21% java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not pr… Tomcat Mitigation only Fix from $1,6002015-02-16