Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mesos MEDIUM 5.9
CVE-2018-8023

Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2…

Fix: 1.4.2+
Fix from $1,600 2018-09-21
Tika MEDIUM 5.5
CVE-2018-8017

In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.

Fix: after 1.18
Fix from $1,600 2018-09-19
Tika HIGH 7.5
CVE-2018-11761EPSS 10%

In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vuln…

Fix: after 1.18
Fix from $1,950 2018-09-19
Tika MEDIUM 5.9
CVE-2018-11762EPSS 5%

In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input …

Fix: after 1.18
Fix from $1,600 2018-09-19
Karaf HIGH 8.8
CVE-2018-11786

In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with ri…

Fix: 4.2.0+
Fix from $1,950 2018-09-18
Karaf HIGH 8.1
CVE-2018-11787

In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and re…

Fix: 3.0.9 / 4.0.9+
Fix from $1,950 2018-09-18
Spamassassin CRITICAL 9.8
CVE-2018-11780EPSS 11%

A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.

Fix: 3.4.2+
Fix from $2,300 2018-09-17
Spamassassin HIGH 7.8
CVE-2018-11781

Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.

Fix: 3.4.2+
Fix from $1,950 2018-09-17
Spamassassin MEDIUM 5.3
CVE-2017-15705EPSS 8%

A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags…

Fix: 3.4.2+
Fix from $1,600 2018-09-17
Camel MEDIUM 5.3
CVE-2018-8041EPSS 10%

Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.

Fix: after 2.21.1
Fix from $1,600 2018-09-17
Mesos HIGH 7.5
CVE-2018-1330

When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked H…

Fix: 1.4.2 / 1.5.1+
Fix from $1,950 2018-09-13
Activemq HIGH 7.4
CVE-2018-11775EPSS 7%

TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack bet…

Fix: 5.15.6+
Fix from $1,950 2018-09-10
Traffic Server HIGH 7.5
CVE-2018-8022EPSS 7%

A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2. To resolve this issue users …

Fix: after 6.2.2
Fix from $1,950 2018-08-29
Traffic Server MEDIUM 5.3
CVE-2018-8040EPSS 7%

Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This affects Apa…

Fix: after 7.1.3
Fix from $1,600 2018-08-29
Traffic Server HIGH 7.5
CVE-2018-1318EPSS 8%

Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server …

Fix: after 7.1.3
Fix from $1,950 2018-08-29
Traffic Server MEDIUM 6.5
CVE-2018-8004EPSS 6%

There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache Traffic Server (ATS). This a…

Fix: after 7.1.3
Fix from $1,600 2018-08-29
Traffic Server MEDIUM 5.3
CVE-2018-8005EPSS 7%

When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. This can cause performance pro…

Fix: after 7.1.3
Fix from $1,600 2018-08-29
Mod Perl CRITICAL 9.8
CVE-2011-2767EPSS 9%

mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the do…

Fix: after 2.0.10
Fix from $2,300 2018-08-26
Sentry HIGH 8.8
CVE-2018-8028

An authenticated user can execute ALTER TABLE EXCHANGE PARTITIONS without being authorized by Apache Sentry before 2.0.1. This can allow an attacker …

Fix: 2.0.1+
Fix from $1,950 2018-08-23
Cayenne HIGH 8.1
CVE-2018-11758

This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler is a desktop GUI tool shippe…

Fix: after 3.1.0
Fix from $1,950 2018-08-22
Struts HIGH 8.1
CVE-2018-11776 KEVEPSS 100%

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by u…

Fix: 2.3.35 / 2.5.17+
Fix from $1,950 2018-08-22
Commons Compress MEDIUM 5.5
CVE-2018-11771EPSS 5%

When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to return the c…

Fix: after 1.17.0
Fix from $1,600 2018-08-16
HTTP Server MEDIUM 6.1
CVE-2016-4975EPSS 20%

Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 …

Mitigation only
Fix from $1,600 2018-08-14
Couchdb HIGH 7.2
CVE-2018-11769EPSS 8%

CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied con…

Fix: 2.2.0+
Fix from $1,950 2018-08-08
Airflow MEDIUM 6.1
CVE-2017-12614

It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and p…

Fix: 1.9.0+
Fix from $1,600 2018-08-06
Tomcat HIGH 7.5
CVE-2018-1336EPSS 21%

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Se…

Fix: after 9.0.7
Fix from $1,950 2018-08-02
Tomcat MEDIUM 5.9
CVE-2018-8037EPSS 12%

If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that cou…

Fix: after 9.0.9
Fix from $1,600 2018-08-02
Axis MEDIUM 6.1
CVE-2018-8032EPSS 11%

Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.

Fix: after 1.4
Fix from $1,600 2018-08-02
Tomcat HIGH 7.5
CVE-2018-8034EPSS 21%

The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0…

Fix: after 9.0.9
Fix from $1,950 2018-08-01
Camel CRITICAL 9.8
CVE-2018-8027EPSS 6%

Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.

Fix: after 2.20.3
Fix from $2,300 2018-07-31