Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Poi MEDIUM 5.5
CVE-2019-12415

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can a…

Fix: after 4.1.0
Fix from $1,600 2019-10-23
Traffic Server HIGH 7.5
CVE-2019-10079

Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't limit the number of setting fra…

Fix: 7.1.7 / 8.0.4+
Fix from $1,950 2019-10-22
Hadoop CRITICAL 9.8
CVE-2019-17195EPSS 11%

Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potenti…

Fix: 7.9+
Fix from $2,300 2019-10-15
Tomee HIGH 7.5
CVE-2019-17359EPSS 9%

The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, vi…

Fix: after 3.0.2.1
Fix from $1,950 2019-10-08
Hadoop HIGH 7.5
CVE-2018-11768EPSS 7%

In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across …

Fix: after 3.1.1
Fix from $1,950 2019-10-04
Mina HIGH 7.5
CVE-2019-0231

Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the cl…

Mitigation only
Fix from $1,950 2019-10-01
HTTP Server CRITICAL 9.1
CVE-2019-10082EPSS 17%

In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during c…

Fix: after 17.3
Fix from $2,300 2019-09-26
Subversion HIGH 7.5
CVE-2019-0203

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain s…

Fix: after 1.11.1
Fix from $1,950 2019-09-26
HTTP Server HIGH 7.2
CVE-2019-10097EPSS 53%

In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specia…

Fix: after 17.3
Fix from $1,950 2019-09-26
Subversion MEDIUM 6.5
CVE-2018-11782

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only …

Fix: after 1.11.1
Fix from $1,600 2019-09-26
HTTP Server MEDIUM 6.1
CVE-2019-10092EPSS 81%

In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the…

Fix: after 9.5
Fix from $1,600 2019-09-26
HTTP Server MEDIUM 6.1
CVE-2019-10098EPSS 74%

In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded new…

Fix: after 2.4.39
Fix from $1,600 2019-09-25
Jspwiki MEDIUM 6.1
CVE-2019-10090

On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related …

Fix: after 2.10.5
Fix from $1,600 2019-09-23
Jspwiki MEDIUM 6.1
CVE-2019-12407

On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related …

Fix: after 2.10.5
Fix from $1,600 2019-09-23
Jspwiki MEDIUM 6.1
CVE-2019-10087

On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related …

Fix: after 2.10.5
Fix from $1,600 2019-09-23
Jspwiki MEDIUM 6.1
CVE-2019-10089

On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related …

Fix: after 2.10.5
Fix from $1,600 2019-09-23
Jspwiki MEDIUM 6.1
CVE-2019-12404

On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related …

Fix: after 2.10.5
Fix from $1,600 2019-09-23
Tapestry CRITICAL 9.8
CVE-2019-10071EPSS 9%

The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the…

Fix: after 5.4.3
Fix from $2,300 2019-09-16
Tapestry HIGH 7.5
CVE-2019-0207

Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the chara…

Fix: after 5.4.4
Fix from $1,950 2019-09-16
Tapestry CRITICAL 9.8
CVE-2019-0195EPSS 15%

Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker fou…

Fix: after 5.4.3
Fix from $2,300 2019-09-16
Ofbiz CRITICAL 9.8
CVE-2019-10074

An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This …

Fix: after 16.11.05
Fix from $2,300 2019-09-11
Ofbiz MEDIUM 6.1
CVE-2019-10073EPSS 5%

The "Blog", "Forum", "Contact Us" screens of the template "ecommerce" application bundled in Apache OFBiz are weak to Stored XSS attacks. Mitigation:…

Fix: after 16.11.05
Fix from $1,600 2019-09-11
Ofbiz CRITICAL 9.8
CVE-2018-17200EPSS 5%

The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpServi…

Fix: after 16.11.05
Fix from $2,300 2019-09-11
Ofbiz CRITICAL 9.8
CVE-2019-0189EPSS 24%

The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and …

Fix: 16.11.06+
Fix from $2,300 2019-09-11
Solr HIGH 7.5
CVE-2019-12401EPSS 7%

Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s upda…

Fix: after 4.10.4
Fix from $1,950 2019-09-10
Traffic Control CRITICAL 9.8
CVE-2019-12405

Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component.…

Mitigation only
Fix from $2,300 2019-09-09
Commons Compress HIGH 7.5
CVE-2019-12402EPSS 16%

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially craf…

Fix: after 14.4.0
Fix from $1,950 2019-08-30
Hbase HIGH 7.5
CVE-2019-15544

An issue was discovered in the protobuf crate before 2.6.0 for Rust. Attackers can exhaust all memory via Vec::reserve calls.

Fix: 1.7.5 / 2.6.0+
Fix from $1,950 2019-08-26
Santuario Xml Security For Java MEDIUM 5.5
CVE-2019-12400

In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static poo…

Fix: 2.1.4+
Fix from $1,600 2019-08-23
Commons Beanutils HIGH 7.3
CVE-2019-10086EPSS 30%

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the clas…

Fix: after 1.9.3
Fix from $1,950 2019-08-20