Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ode HIGH 7.5
CVE-2018-1316

The ODE process deployment web service was sensible to deployment messages with forged names. Using a path for the name was allowing directory traver…

Fix: after 1.3.2
Fix from $1,950 2018-03-05
Xerces C\+\+ CRITICAL 9.8
CVE-2017-12627EPSS 8%

In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain condition…

Fix: 3.2.1+
Fix from $2,300 2018-03-01
Tomcat MEDIUM 5.9
CVE-2018-1304EPSS 17%

The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 t…

Fix: after 9.0.4
Fix from $1,600 2018-02-28
Openmeetings MEDIUM 6.5
CVE-2018-1286

In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny servi…

Fix: after 4.0.1
Fix from $1,600 2018-02-28
Traffic Server HIGH 8.6
CVE-2017-5660

There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issu…

Fix: after 6.2.0
Fix from $1,950 2018-02-27
Traffic Server HIGH 7.5
CVE-2017-7671

There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can c…

Fix: after 6.2.0
Fix from $1,950 2018-02-27
Hupa MEDIUM 6.1
CVE-2012-3536

Two XSS vulnerabilities were fixed in message list and view in the Hupa Webmail application from the Apache James project. An attacker could send a c…

Fix: 0.0.3+
Fix from $1,600 2018-02-27
Geode CRITICAL 9.8
CVE-2017-15692

In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains acce…

Fix: 1.4.0+
Fix from $2,300 2018-02-27
Geode HIGH 7.5
CVE-2017-15693

In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause t…

Fix: 1.4.0+
Fix from $1,950 2018-02-27
Geode HIGH 7.5
CVE-2017-15696

When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration req…

Fix: after 1.3.0
Fix from $1,950 2018-02-26
Tomcat MEDIUM 6.5
CVE-2018-1305EPSS 14%

Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 …

Fix: after 8.5.27
Fix from $1,600 2018-02-23
Vcl HIGH 8.8
CVE-2013-0267

The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated user…

Fix: 2.3.2+
Fix from $1,950 2018-02-21
Qpid MEDIUM 6.5
CVE-2015-0203EPSS 9%

The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via an AMQP message wi…

Fix: after 0.30
Fix from $1,600 2018-02-21
Juddi MEDIUM 6.5
CVE-2009-4267

The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof log entries via the numRows p…

Mitigation only
Fix from $1,600 2018-02-19
Karaf MEDIUM 6.5
CVE-2016-8750EPSS 5%

Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly a…

Fix: 4.0.8+
Fix from $1,600 2018-02-19
Oozie MEDIUM 6.5
CVE-2017-15712

Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malici…

Mitigation only
Fix from $1,600 2018-02-19
Jmeter CRITICAL 9.8
CVE-2018-1287

In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an at…

Mitigation only
Fix from $2,300 2018-02-14
Qpid Dispatch MEDIUM 6.5
CVE-2017-15699

A Denial of Service vulnerability was found in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0. To exploit this vulnerability, a remote user mus…

Patch available
Fix from $1,600 2018-02-13
Jmeter CRITICAL 9.8
CVE-2018-1297EPSS 10%

When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access …

Mitigation only
Fix from $2,300 2018-02-13
Thrift HIGH 8.8
CVE-2016-5397EPSS 7%

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affe…

Fix: after 0.9.3
Fix from $1,950 2018-02-12
Couchdb HIGH 7.8
CVE-2016-8742

The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file p…

No fix yet
Fix from $1,950 2018-02-12
Juddi HIGH 8.1
CVE-2018-1307

In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data…

Fix: after 3.3.4
Fix from $1,950 2018-02-09
Qpid Broker J MEDIUM 5.9
CVE-2018-1298

A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocols 0-8, …

Mitigation only
Fix from $1,600 2018-02-09
Allura HIGH 7.5
CVE-2018-1299

In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application. Some webservers used with A…

Fix: 1.8.0+
Fix from $1,950 2018-02-06
Cloudstack CRITICAL 9.8
CVE-2016-6813EPSS 6%

Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is a…

Fix: after 4.8.1.0
Fix from $2,300 2018-02-06
Cordova HIGH 7.4
CVE-2017-3160

After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, the scripts will fetch Gradle o…

Fix: 6.1.2+
Fix from $1,950 2018-02-01
Tomcat Native MEDIUM 5.9
CVE-2017-15698

When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly h…

Fix: after 1.2.14
Fix from $1,600 2018-01-31
Tomcat MEDIUM 5.3
CVE-2017-15706EPSS 6%

As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 inc…

Fix: after 8.5.23
Fix from $1,600 2018-01-31
Poi HIGH 7.5
CVE-2017-12626EPSS 10%

Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and m…

Fix: 3.17+
Fix from $1,950 2018-01-29
Nifi MEDIUM 5.0
CVE-2017-15703

Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a den…

Fix: after 1.4.0
Fix from $1,600 2018-01-25