Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HTTP Server HIGH 7.5
CVE-2019-10081EPSS 15%

HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing r…

Fix: after 2.4.39
Fix from $1,950 2019-08-15
Traffic Server HIGH 7.5
CVE-2019-9518EPSS 25%

Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of fra…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9511EPSS 60%

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of ser…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9512EPSS 83%

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/…

Fix: 8.16.1 / 10.16.3+
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9513EPSS 82%

Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request strea…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9514EPSS 83%

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and s…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
Traffic Server HIGH 7.5
CVE-2019-9515EPSS 87%

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS f…

Fix: after 8.0.3
Fix from $1,950 2019-08-13
HTTP Server HIGH 7.5
CVE-2019-9517EPSS 28%

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens th…

Fix: 2.4.40+
Fix from $1,950 2019-08-13
Traffic Server MEDIUM 6.5
CVE-2019-9516EPSS 56%

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with …

Fix: after 8.0.3
Fix from $1,600 2019-08-13
Ranger MEDIUM 6.1
CVE-2019-12397

Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apach…

Fix: after 1.2.0
Fix from $1,600 2019-08-08
Spark HIGH 7.5
CVE-2019-10099

Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true. This inc…

Fix: 2.3.2+
Fix from $1,950 2019-08-07
Tika HIGH 8.8
CVE-2019-10088

A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 o…

Fix: after 1.21
Fix from $1,950 2019-08-02
Tika HIGH 7.8
CVE-2019-10094

A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Ti…

Fix: after 1.21
Fix from $1,950 2019-08-02
Tika MEDIUM 6.5
CVE-2019-10093

In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs…

Fix: after 1.21
Fix from $1,600 2019-08-02
Solr HIGH 7.2
CVE-2019-0193 KEVEPSS 84%

In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the wh…

Fix: 7.7.3 / 8.1.2+
Fix from $1,950 2019-08-01
Virtual Computing Lab CRITICAL 9.8
CVE-2018-11773

Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as a…

Fix: after 2.5
Fix from $2,300 2019-07-29
Virtual Computing Lab HIGH 7.2
CVE-2018-11774

Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. The form data is then used in…

Fix: after 2.5
Fix from $1,950 2019-07-29
Virtual Computing Lab HIGH 7.2
CVE-2018-11772

Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previously selected in the privileg…

Fix: after 2.5
Fix from $1,950 2019-07-29
Tomee CRITICAL 9.8
CVE-2019-13990EPSS 16%

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

Fix: 2.3.2+
Fix from $2,300 2019-07-26
Storm HIGH 7.5
CVE-2019-0202

The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-i…

Fix: after 1.2.2
Fix from $1,950 2019-07-26
Storm CRITICAL 9.8
CVE-2018-11779

In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI d…

Fix: after 1.2.2
Fix from $2,300 2019-07-26
Roller MEDIUM 6.1
CVE-2019-0234

A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user inpu…

Mitigation only
Fix from $1,600 2019-07-15
Kafka HIGH 8.8
CVE-2018-17196EPSS 5%

In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL val…

Fix: after 2.1.0
Fix from $1,950 2019-07-11
Tomcat HIGH 7.5
CVE-2019-10072EPSS 73%

The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.1…

Fix: after 9.0.19
Fix from $1,950 2019-06-21
Geode MEDIUM 6.5
CVE-2017-15694

When an Apache Geode server versions 1.0.0 to 1.8.0 is operating in secure mode, a user with write permissions for specific data regions can modify i…

Fix: after 1.8.0
Fix from $1,600 2019-06-21
Allura MEDIUM 6.1
CVE-2019-10085EPSS 5%

In Apache Allura prior to 1.11.0, a vulnerability exists for stored XSS on the user dropdown selector when creating or editing tickets. The XSS execu…

Fix: 1.11.0+
Fix from $1,600 2019-06-19
HTTP Server MEDIUM 5.3
CVE-2019-0196EPSS 20%

A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access fre…

Fix: after 2.4.38
Fix from $1,600 2019-06-11
HTTP Server MEDIUM 5.3
CVE-2019-0220EPSS 18%

A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/')…

Fix: after 2.4.38
Fix from $1,600 2019-06-11
Fineract CRITICAL 9.8
CVE-2018-11800EPSS 5%

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts …

Fix: 1.3.0+
Fix from $2,300 2019-06-11
Fineract CRITICAL 9.8
CVE-2018-11801EPSS 5%

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related…

Fix: 1.3.0+
Fix from $2,300 2019-06-11