Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Activemq HIGH 7.5
CVE-2019-0222EPSS 12%

In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.

Fix: 19.1.0.0.1+
Fix from $1,950 2019-03-28
Jspwiki HIGH 7.5
CVE-2019-0225EPSS 10%

A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could b…

Fix: 2.11.0+
Fix from $1,950 2019-03-28
Jspwiki MEDIUM 6.1
CVE-2019-0224EPSS 5%

In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on th…

Fix: after 2.10.5
Fix from $1,600 2019-03-28
Mesos HIGH 7.8
CVE-2019-0204

A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command exec…

Fix: 1.4.3 / 1.5.3+
Fix from $1,950 2019-03-25
Karaf MEDIUM 6.5
CVE-2019-0191

Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes …

Fix: 4.2.3+
Fix from $1,600 2019-03-21
Heron HIGH 7.5
CVE-2018-11789EPSS 7%

When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host. Example woule …

Fix: after 0.17.8
Fix from $1,950 2019-03-21
Hadoop HIGH 7.4
CVE-2018-11767

In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-d…

Fix: after 2.9.1
Fix from $1,950 2019-03-21
Solr HIGH 7.5
CVE-2017-3164EPSS 19%

Server Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding whitelist …

Fix: after 7.6.0
Fix from $1,950 2019-03-08
Solr CRITICAL 9.8
CVE-2019-0192EPSS 78%

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it…

Fix: after 6.6.5
Fix from $2,300 2019-03-07
Traffic Server HIGH 7.5
CVE-2018-11783

sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plug…

Fix: after 8.0.1
Fix from $1,950 2019-03-07
Qpid Broker J HIGH 7.5
CVE-2019-0200

A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 6.0.0-7.0.6 (inclusive) and 7.1.0 which allows an unauthenticated attack…

Fix: after 7.0.6
Fix from $1,950 2019-03-06
Jmeter CRITICAL 9.8
CVE-2019-0187

Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a…

Mitigation only
Fix from $2,300 2019-03-06
Mesos HIGH 7.5
CVE-2018-11793

When parsing a JSON payload with deeply nested JSON structures, the parser in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.1, 1.6.0 …

Fix: 1.4.3 / 1.5.2+
Fix from $1,950 2019-03-05
Airflow MEDIUM 5.5
CVE-2018-20244

In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascr…

Fix: 1.10.2+
Fix from $1,600 2019-02-27
Jspwiki MEDIUM 6.1
CVE-2018-20242EPSS 5%

A carefully crafted URL could trigger an XSS vulnerability on Apache JSPWiki, from versions up to 2.10.5, which could lead to session hijacking.

Fix: after 2.10.5
Fix from $1,600 2019-02-11
Hadoop HIGH 7.5
CVE-2018-1296

In Apache Hadoop 3.0.0-alpha1 to 3.0.0, 2.9.0, 2.8.0 to 2.8.3, and 2.5.0 to 2.7.5, HDFS exposes extended attribute key/value pairs during listXAttrs,…

Fix: after 2.7.5
Fix from $1,950 2019-02-07
Guacamole HIGH 7.5
CVE-2018-1340

Prior to 1.0.0, Apache Guacamole used a cookie for client-side storage of the user's session token. This cookie lacked the "secure" flag, which could…

Fix: after 0.9.14
Fix from $1,950 2019-02-07
Subversion HIGH 7.5
CVE-2018-11803EPSS 58%

Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the clie…

Fix: after 1.10.3
Fix from $1,950 2019-02-05
Spark MEDIUM 5.5
CVE-2018-11760

When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark applicat…

Fix: after 2.3.1
Fix from $1,600 2019-02-04
Openoffice HIGH 7.8
CVE-2018-11790

When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs…

Fix: after 4.1.5
Fix from $1,950 2019-01-31
HTTP Server HIGH 7.5
CVE-2018-17199EPSS 21%

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expir…

Fix: after 2.4.37
Fix from $1,950 2019-01-30
HTTP Server HIGH 7.5
CVE-2019-0190EPSS 59%

A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to e…

Mitigation only
Fix from $1,950 2019-01-30
HTTP Server MEDIUM 5.3
CVE-2018-17189EPSS 20%

In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unn…

Mitigation only
Fix from $1,600 2019-01-30
Airflow CRITICAL 9.8
CVE-2017-17836

In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airfl…

Fix: after 1.8.2
Fix from $2,300 2019-01-23
Airflow HIGH 8.8
CVE-2017-15720

In Apache Airflow 1.8.2 and earlier, an authenticated user can execute code remotely on the Airflow webserver by creating a special object.

Fix: after 1.8.2
Fix from $1,950 2019-01-23
Airflow HIGH 8.8
CVE-2017-17835

In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.

Fix: after 1.8.2
Fix from $1,950 2019-01-23
Airflow HIGH 7.5
CVE-2018-20245

The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of e…

Fix: 1.10.1+
Fix from $1,950 2019-01-23
Mesos MEDIUM 6.5
CVE-2018-1000420

An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read …

Fix: after 0.17.1
Fix from $1,600 2019-01-09
Mesos MEDIUM 6.5
CVE-2018-1000421

An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read …

Fix: after 0.17.1
Fix from $1,600 2019-01-09
Thrift HIGH 7.5
CVE-2018-1320EPSS 8%

Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.…

Fix: 11.2.0.3.23 / 12.2.0.1.19+
Fix from $1,950 2019-01-07