Vulnerability index

Browse CVEs

398 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2012-0880 Apache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes has… Xerces C\+\+ Mitigation only Fix from $1,9502017-08-08 HIGH 7.5 CVE-2017-9801EPSS 6% When a call-site passes a subject for an email that contains line-breaks in Apache Commons Email 1.0 through 1.4, the caller can add arbitrary SMTP h… Commons Email Mitigation only Fix from $1,9502017-08-07 HIGH 7.5 CVE-2016-0736EPSS 49% In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either C… HTTP Server No fix yet Fix from $1,9502017-07-27 HIGH 7.5 CVE-2016-2161EPSS 21% In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to cras… HTTP Server Mitigation only Fix from $1,9502017-07-27 HIGH 7.5 CVE-2017-7659EPSS 54% A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash the serve… HTTP Server Mitigation only Fix from $1,9502017-07-26 HIGH 7.5 CVE-2017-7688 Apache OpenMeetings 1.0.0 updates user password in insecure manner. Openmeetings No fix yet Fix from $1,9502017-07-17 MEDIUM 5.3 CVE-2017-7685 Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH. Openmeetings Mitigation only Fix from $1,6002017-07-17 CRITICAL 10.0 CVE-2017-7664 Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0. Openmeetings Mitigation only Fix from $2,3002017-07-17 CRITICAL 9.8 CVE-2017-7673 Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms … Openmeetings Mitigation only Fix from $2,3002017-07-17 HIGH 8.8 CVE-2017-7666 Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks. Openmeetings Mitigation only Fix from $1,9502017-07-17 HIGH 8.8 CVE-2017-7681 Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the … Openmeetings Mitigation only Fix from $1,9502017-07-17 HIGH 8.2 CVE-2017-7682 Apache OpenMeetings 3.2.0 is vulnerable to parameter manipulation attacks, as a result attacker has access to restricted areas. Openmeetings Mitigation only Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-7680 Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file. This allows for flash content to be loaded from untrusted domains. Openmeetings Mitigation only Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-7683 Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure. Openmeetings Mitigation only Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-7684 Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded. An attacker can cause a denial of service by uploading multiple large files… Openmeetings Mitigation only Fix from $1,9502017-07-17 MEDIUM 6.1 CVE-2017-7663 Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0. Openmeetings Mitigation only Fix from $1,6002017-07-17 HIGH 7.2 CVE-2015-0249 The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary… Roller Mitigation only Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-9789EPSS 10% When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, r… HTTP Server Mitigation only Fix from $1,9502017-07-13 HIGH 7.5 CVE-2017-9787EPSS 10% When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts versio… Struts Mitigation only Fix from $1,9502017-07-13 MEDIUM 5.9 CVE-2017-7672EPSS 9% If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used t… Struts Mitigation only Fix from $1,6002017-07-13 CRITICAL 9.8 CVE-2017-5640 It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to ski… Impala Mitigation only Fix from $2,3002017-07-10 HIGH 7.5 CVE-2017-5652 During a routine security analysis, it was found that one of the ports in Apache Impala (incubating) 2.7.0 to 2.8.0 sent data in plaintext even when … Impala Mitigation only Fix from $1,9502017-07-10 HIGH 7.5 CVE-2017-7660EPSS 6% Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node… Solr Mitigation only Fix from $1,9502017-07-07 HIGH 7.5 CVE-2017-7686 Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality… Ignite Mitigation only Fix from $1,9502017-06-28 CRITICAL 9.8 CVE-2017-3169EPSS 20% In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_con… HTTP Server Mitigation only Fix from $2,3002017-06-20 MEDIUM 6.5 CVE-2016-5004EPSS 6% The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource … Ws Xmlrpc No fix yet Fix from $1,6002017-06-06 HIGH 7.5 CVE-2017-5664EPSS 17% The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is configured for the error that occ… Tomcat Mitigation only Fix from $1,9502017-06-06 HIGH 7.5 CVE-2017-7669 In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. W… Hadoop Mitigation only Fix from $1,9502017-06-05 HIGH 7.5 CVE-2016-3083 Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the server's … Hive Mitigation only Fix from $1,9502017-05-30 MEDIUM 6.8 CVE-2017-5646 For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing … Knox Mitigation only Fix from $1,6002017-05-26