Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Log4j CRITICAL 9.8
CVE-2019-17571EPSS 69%

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbi…

Fix: 4.14.3+
Fix from $2,300 2019-12-20
Xerces C\+\+ HIGH 8.1
CVE-2018-1311EPSS 10%

The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been …

Fix: 3.2.5+
Fix from $1,950 2019-12-18
Superset MEDIUM 5.3
CVE-2019-12413

In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access to, by using a specially cra…

Fix: 0.31+
Fix from $1,600 2019-12-16
Superset MEDIUM 5.3
CVE-2019-12414

In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in SQLLab

Fix: 0.32+
Fix from $1,600 2019-12-16
Qpid Cpp HIGH 7.5
CVE-2014-0212

qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors

Mitigation only
Fix from $1,950 2019-12-13
Spamassassin HIGH 7.5
CVE-2019-12420EPSS 7%

In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the r…

Fix: 3.4.3+
Fix from $1,950 2019-12-12
Spamassassin MEDIUM 6.7
CVE-2018-11805

In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits ca…

Fix: 3.4.3+
Fix from $1,600 2019-12-12
Struts HIGH 8.8
CVE-2012-1592EPSS 29%

A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbit…

Mitigation only
Fix from $1,950 2019-12-05
Olingo HIGH 7.5
CVE-2019-17555

The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method w…

Fix: after 4.6.0
Fix from $1,950 2019-12-04
Olingo CRITICAL 9.8
CVE-2019-17556

Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being …

Fix: after 4.6.0
Fix from $2,300 2019-12-04
Olingo MEDIUM 5.5
CVE-2019-17554EPSS 12%

The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Requ…

Fix: after 4.6.0
Fix from $1,600 2019-12-04
Mod Fcgid HIGH 8.8
CVE-2016-1000104

A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.

Fix: after 2016-07-07
Fix from $1,950 2019-12-03
Openoffice HIGH 7.8
CVE-2011-2177

OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the OpenOffice.org suite tools.

Mitigation only
Fix from $1,950 2019-11-27
Ofbiz HIGH 7.5
CVE-2011-3600EPSS 16%

The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with exe…

Fix: after 16.11.04
Fix from $1,950 2019-11-26
Nifi HIGH 8.8
CVE-2019-12421

When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi versions 1.0.0 to 1.9.2, NiFi invalidates the authenticat…

Fix: after 1.9.2
Fix from $1,950 2019-11-19
Nifi MEDIUM 6.5
CVE-2019-10080

The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML f…

Fix: after 1.9.2
Fix from $1,600 2019-11-19
Nifi MEDIUM 5.3
CVE-2019-10083

When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most …

Fix: after 1.9.2
Fix from $1,600 2019-11-19
Shiro HIGH 7.5
CVE-2019-12422EPSS 9%

Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding attack.

Fix: 1.4.2+
Fix from $1,950 2019-11-18
Solr CRITICAL 9.8
CVE-2019-12409EPSS 22%

The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh…

No fix yet
Fix from $2,300 2019-11-18
Atlas MEDIUM 6.1
CVE-2019-10070

Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality

Mitigation only
Fix from $1,600 2019-11-18
Qpid Cpp MEDIUM 6.5
CVE-2009-5004

qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .

Mitigation only
Fix from $1,600 2019-11-09
Arrow HIGH 7.5
CVE-2019-12408

It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had a uniniti…

Fix: after 0.14.1
Fix from $1,950 2019-11-08
Arrow HIGH 7.5
CVE-2019-12410

While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory A…

Fix: after 0.14.1
Fix from $1,950 2019-11-08
Cxf CRITICAL 9.8
CVE-2019-12419EPSS 14%

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulne…

Fix: 3.2.11 / 3.3.4+
Fix from $2,300 2019-11-06
Cxf MEDIUM 6.5
CVE-2019-12406EPSS 6%

Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility o…

Fix: 3.2.11 / 3.3.4+
Fix from $1,600 2019-11-06
Impala HIGH 7.5
CVE-2019-10084

In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions o…

Fix: after 3.2.0
Fix from $1,950 2019-11-05
Struts CRITICAL 9.8
CVE-2011-3923EPSS 89%

Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.

Fix: 2.3.1.2+
Fix from $2,300 2019-11-01
Thrift HIGH 7.5
CVE-2019-0205EPSS 9%

In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because…

Fix: after 0.12.0
Fix from $1,950 2019-10-29
Thrift HIGH 7.5
CVE-2019-0210EPSS 7%

In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.

Fix: after 0.12.0
Fix from $1,950 2019-10-29
Hadoop HIGH 7.5
CVE-2012-2945

Hadoop 1.0.3 contains a symlink vulnerability.

No fix yet
Fix from $1,950 2019-10-29