Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Orc HIGH 7.5
CVE-2018-8015

In Apache ORC 1.0.0 to 1.4.3 a malformed ORC file can trigger an endlessly recursive function call in the C++ or Java parser. The impact of this bug …

Fix: after 1.4.3
Fix from $1,950 2018-05-18
Tomcat CRITICAL 9.8
CVE-2018-8014EPSS 22%

The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are ins…

Fix: after 9.0.8
Fix from $2,300 2018-05-16
Derby MEDIUM 5.3
CVE-2018-1313

In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a database whose lo…

Fix: after 10.14.1.0
Fix from $1,600 2018-05-07
Ambari MEDIUM 5.3
CVE-2018-8003

Apache Ambari, versions 1.4.0 to 2.6.1, is susceptible to a directory traversal attack allowing an unauthenticated user to craft an HTTP request whic…

Fix: after 2.6.1
Fix from $1,600 2018-05-03
Openoffice HIGH 7.5
CVE-2018-10583EPSS 79%

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB co…

No fix yet
Fix from $1,950 2018-05-01
Uimaj MEDIUM 6.5
CVE-2017-15691EPSS 9%

In Apache uimaj prior to 2.10.2, Apache uimaj 3.0.0-xxx prior to 3.0.0-beta, Apache uima-as prior to 2.10.2, Apache uimaFIT prior to 2.4.0, Apache ui…

Fix: 2.2.2 / 2.4.0+
Fix from $1,600 2018-04-26
Tika HIGH 8.1
CVE-2018-1335EPSS 94%

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the com…

Fix: 1.18+
Fix from $1,950 2018-04-25
Tika MEDIUM 5.5
CVE-2018-1338

A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.

Fix: 1.18+
Fix from $1,600 2018-04-25
Tika MEDIUM 5.5
CVE-2018-1339

A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.

Fix: 1.18+
Fix from $1,600 2018-04-25
Fineract CRITICAL 9.8
CVE-2018-1290

In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL para…

Mitigation only
Fix from $2,300 2018-04-20
Fineract HIGH 8.8
CVE-2018-1289

In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain…

Mitigation only
Fix from $1,950 2018-04-20
Fineract HIGH 8.1
CVE-2018-1291

Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entities with …

Mitigation only
Fix from $1,950 2018-04-20
Fineract HIGH 8.1
CVE-2018-1292

Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/u…

Mitigation only
Fix from $1,950 2018-04-20
Solr HIGH 7.5
CVE-2018-1308EPSS 21%

This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` …

Fix: after 7.2.1
Fix from $1,950 2018-04-09
Hive CRITICAL 9.1
CVE-2018-1282EPSS 6%

This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup th…

Fix: after 2.3.2
Fix from $2,300 2018-04-05
Ignite CRITICAL 9.8
CVE-2018-1295EPSS 6%

In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes i…

Fix: after 2.3.0
Fix from $2,300 2018-04-02
Struts HIGH 7.5
CVE-2018-1327EPSS 9%

The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with special…

Fix: after 2.5.14.1
Fix from $1,950 2018-03-27
HTTP Server CRITICAL 9.8
CVE-2018-1312EPSS 16%

In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly g…

Mitigation only
Fix from $2,300 2018-03-26
HTTP Server HIGH 8.1
CVE-2017-15715EPSS 86%

In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than…

Fix: after 2.4.29
Fix from $1,950 2018-03-26
HTTP Server HIGH 7.5
CVE-2017-15710EPSS 18%

In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-La…

No fix yet
Fix from $1,950 2018-03-26
HTTP Server HIGH 7.5
CVE-2018-1303EPSS 70%

A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing…

Fix: after 2.4.29
Fix from $1,950 2018-03-26
HTTP Server MEDIUM 5.9
CVE-2018-1301EPSS 15%

A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is re…

Fix: after 2.4.29
Fix from $1,600 2018-03-26
HTTP Server MEDIUM 5.9
CVE-2018-1302EPSS 13%

When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially…

Fix: after 2.4.29
Fix from $1,600 2018-03-26
HTTP Server MEDIUM 5.3
CVE-2018-1283EPSS 10%

In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a r…

Fix: after 2.4.29
Fix from $1,600 2018-03-26
Commons Email HIGH 7.5
CVE-2018-1294

If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and that input co…

Fix: after 1.4
Fix from $1,950 2018-03-20
Syncope HIGH 7.2
CVE-2018-1321EPSS 18%

An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and …

Fix: 1.2.11 / 2.0.8+
Fix from $1,950 2018-03-20
Commons Compress MEDIUM 5.5
CVE-2018-1324

A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and Z…

Fix: after 8.0.27
Fix from $1,600 2018-03-16
Allura MEDIUM 6.1
CVE-2018-1319

In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted…

Fix: after 1.8.0
Fix from $1,600 2018-03-15
Tomcat Jk Connector HIGH 7.5
CVE-2018-1323EPSS 46%

The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-…

Fix: after 1.2.42
Fix from $1,950 2018-03-12
Artemis HIGH 7.5
CVE-2017-12174EPSS 6%

It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when rec…

Fix: 2.4.0+
Fix from $1,950 2018-03-07