Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2014-8152EPSS 6% Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a cr… Santuario Xml Security For Java Mitigation only Fix from $1,6002015-01-21 MEDIUM 5.0 CVE-2014-3583EPSS 11% The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause … HTTP Server Mitigation only Fix from $1,6002014-12-15 MEDIUM 6.8 CVE-2014-7809 Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mecha… Struts No fix yet Fix from $1,6002014-12-10 MEDIUM 5.0 CVE-2014-7807 Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, … Cloudstack Mitigation only Fix from $1,6002014-12-10 MEDIUM 5.0 CVE-2014-3627 The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster u… Hadoop Mitigation only Fix from $1,6002014-12-05 HIGH 7.5 CVE-2014-0074EPSS 5% Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an e… Shiro No fix yet Fix from $1,9502014-10-06 HIGH 10.0 CVE-2014-3525 Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors,… Traffic Server No fix yet Fix from $1,9502014-08-22 MEDIUM 5.0 CVE-2014-3503EPSS 6% Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via… Syncope No fix yet Fix from $1,6002014-07-11 MEDIUM 5.0 CVE-2014-0075EPSS 20% Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6.0.40, 7.… Tomcat Mitigation only Fix from $1,6002014-05-31 MEDIUM 5.8 CVE-2014-0116EPSS 7% CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass me… Struts Mitigation only Fix from $1,6002014-05-08 MEDIUM 5.8 CVE-2013-4286EPSS 17% Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle c… Tomcat Mitigation only Fix from $1,6002014-02-26 MEDIUM 5.0 CVE-2013-2055 Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive… Wicket Mitigation only Fix from $1,6002014-02-10 MEDIUM 6.4 CVE-2012-5575EPSS 6% Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowe… Cxf Mitigation only Fix from $1,6002013-08-19 MEDIUM 5.8 CVE-2013-2248EPSS 95% Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and cond… Struts Mitigation only Fix from $1,6002013-07-20 HIGH 7.5 CVE-2013-1768EPSS 10% The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace d… Openjpa Mitigation only Fix from $1,9502013-07-11 MEDIUM 5.0 CVE-2013-1847EPSS 51% The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of se… Subversion Mitigation only Fix from $1,6002013-05-02 MEDIUM 5.0 CVE-2013-1884EPSS 51% The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault… Subversion Mitigation only Fix from $1,6002013-05-02 MEDIUM 5.0 CVE-2012-5885EPSS 9% The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.… Tomcat Mitigation only Fix from $1,6002012-11-17 MEDIUM 5.0 CVE-2012-5886EPSS 9% The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches informatio… Tomcat Mitigation only Fix from $1,6002012-11-17 MEDIUM 5.0 CVE-2012-2733EPSS 9% java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not… Tomcat Mitigation only Fix from $1,6002012-11-16 HIGH 10.0 CVE-2012-4501EPSS 8% Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user acc… Cloudstack Mitigation only Fix from $1,9502012-10-26 MEDIUM 6.4 CVE-2012-5351EPSS 5% Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signatur… Axis2 Mitigation only Fix from $1,6002012-10-09 MEDIUM 5.8 CVE-2012-4418EPSS 6% Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack." Axis2 No fix yet Fix from $1,6002012-10-09 MEDIUM 6.8 CVE-2012-4386 The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote… Struts Mitigation only Fix from $1,6002012-09-05 HIGH 7.5 CVE-2012-3376 DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same B… Hadoop Mitigation only Fix from $1,9502012-07-12 HIGH 7.5 CVE-2011-3620EPSS 5% Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messagin… Qpid Mitigation only Fix from $1,9502012-05-03 MEDIUM 6.5 CVE-2012-1574 The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used i… Hadoop Mitigation only Fix from $1,6002012-04-12 MEDIUM 5.0 CVE-2012-1089EPSS 5% Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-applicati… Wicket Mitigation only Fix from $1,6002012-03-23 MEDIUM 5.0 CVE-2011-3375EPSS 7% Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request object… Tomcat Mitigation only Fix from $1,6002012-01-19 MEDIUM 5.0 CVE-2012-0022EPSS 11% Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote… Tomcat Mitigation only Fix from $1,6002012-01-19