Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Servicecomb HIGH 7.5
CVE-2021-21501

Improper configuration will cause ServiceComb ServiceCenter Directory Traversal problem in ServcieCenter 1.x.x versions and fixed in 2.0.0.

Fix: 2.0.0+
Fix from $1,950 2021-08-10
Juddi CRITICAL 9.8
CVE-2021-37578

Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provides an alternate transport fo…

Fix: 3.3.10+
Fix from $2,300 2021-07-29
Directory Studio HIGH 7.5
CVE-2021-33900

While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-…

Fix: after 1.5.3
Fix from $1,950 2021-07-26
Impala HIGH 7.5
CVE-2021-28131

Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala lo…

Fix: 4.0.0+
Fix from $1,950 2021-07-22
Ant MEDIUM 5.5
CVE-2021-36373

When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memo…

Fix: 1.9.16 / 1.10.11+
Fix from $1,600 2021-07-14
Ant MEDIUM 5.5
CVE-2021-36374

When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to…

Fix: 1.9.16 / 1.10.11+
Fix from $1,600 2021-07-14
Commons Compress HIGH 7.5
CVE-2021-35515EPSS 12%

When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This cou…

Fix: after 18.3
Fix from $1,950 2021-07-13
Commons Compress HIGH 7.5
CVE-2021-35516EPSS 12%

When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error ev…

Fix: after 18.3
Fix from $1,950 2021-07-13
Commons Compress HIGH 7.5
CVE-2021-35517EPSS 11%

When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error e…

Fix: after 18.3
Fix from $1,950 2021-07-13
Commons Compress HIGH 7.5
CVE-2021-36090EPSS 13%

When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error e…

Fix: 1.21+
Fix from $1,950 2021-07-13
Tomcat HIGH 7.5
CVE-2021-30639EPSS 7%

A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error…

Fix: 5.10.0 / 23.1+
Fix from $1,950 2021-07-12
Tomcat MEDIUM 6.5
CVE-2021-30640EPSS 10%

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of …

Fix: 7.0.109 / 8.5.66+
Fix from $1,600 2021-07-12
Tomcat MEDIUM 5.3
CVE-2021-33037EPSS 75%

Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some c…

Fix: after 10.0.6
Fix from $1,600 2021-07-12
Sshd MEDIUM 6.5
CVE-2021-30129

A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP …

Fix: 2.7.0+
Fix from $1,600 2021-07-12
Jena Fuseki MEDIUM 6.1
CVE-2021-33192

A vulnerability in the HTML pages of Apache Jena Fuseki allows an attacker to execute arbitrary javascript on certain page views. This issue affects …

Fix: 4.1.0+
Fix from $1,600 2021-07-05
Druid MEDIUM 6.5
CVE-2021-26920EPSS 10%

In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticate…

Fix: 0.22.0+
Fix from $1,600 2021-07-02
Traffic Server CRITICAL 9.8
CVE-2021-35474

Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.…

Fix: after 9.0.1
Fix from $2,300 2021-06-30
Traffic Server HIGH 7.5
CVE-2021-32566

Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Se…

Fix: after 9.0.1
Fix from $1,950 2021-06-30
Traffic Server HIGH 7.5
CVE-2021-32567

Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This issue affects Apache Traffic Se…

Fix: after 9.0.1
Fix from $1,950 2021-06-30
Traffic Server HIGH 7.5
CVE-2021-27577

Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic S…

Fix: after 9.0.1
Fix from $1,950 2021-06-29
Traffic Server HIGH 7.5
CVE-2021-32565

Invalid values in the Content-Length header sent to Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic S…

Fix: after 9.0.1
Fix from $1,950 2021-06-29
Nuttx CRITICAL 9.8
CVE-2021-26461EPSS 5%

Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignmen…

Fix: 10.1.0+
Fix from $2,300 2021-06-21
Cxf HIGH 7.5
CVE-2021-30468EPSS 7%

A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thr…

Fix: 3.3.11 / 3.4.4+
Fix from $1,950 2021-06-16
Solr HIGH 7.5
CVE-2021-33813EPSS 19%

An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.

Fix: after 2.0.6
Fix from $1,950 2021-06-16
Chainsaw CRITICAL 9.8
CVE-2020-9493

A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.

Fix: 1.2.18.1 / 2.0+
Fix from $2,300 2021-06-16
HTTP Server HIGH 7.5
CVE-2021-31618EPSS 51%

Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server…

Patch available
Fix from $1,950 2021-06-15
Pdfbox MEDIUM 5.5
CVE-2021-31811

In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version …

Fix: after 14.3.0
Fix from $1,600 2021-06-12
Pdfbox MEDIUM 5.5
CVE-2021-31812

In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 a…

Fix: after 2.0.23
Fix from $1,600 2021-06-12
HTTP Server CRITICAL 9.8
CVE-2021-26691EPSS 68%

In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow

Fix: 18.1.0.1.0+
Fix from $2,300 2021-06-10
HTTP Server HIGH 7.5
CVE-2020-13950EPSS 49%

Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using bot…

Fix: after 2.4.46
Fix from $1,950 2021-06-10