Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hadoop CRITICAL 9.8
CVE-2017-15718

The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Application…

Mitigation only
Fix from $2,300 2018-01-24
Nifi CRITICAL 9.8
CVE-2017-15697

A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fi…

Fix: after 1.4.0
Fix from $2,300 2018-01-23
Nifi HIGH 7.5
CVE-2017-12632

A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and …

Fix: after 1.4.0
Fix from $1,950 2018-01-23
Hadoop MEDIUM 6.5
CVE-2017-15713

Vulnerability in Apache Hadoop 0.23.x, 2.x before 2.7.5, 2.8.x before 2.8.3, and 3.0.0-alpha through 3.0.0-beta1 allows a cluster user to expose priv…

Fix: after 2.8.2
Fix from $1,600 2018-01-19
Guacamole HIGH 8.1
CVE-2017-3158

A race condition in Guacamole's terminal emulator in versions 0.9.5 through 0.9.10-incubating could allow writes of blocks of printed data to overlap…

Fix: after 0.9.9
Fix from $1,950 2018-01-18
Groovy CRITICAL 9.8
CVE-2016-6814EPSS 17%

When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java se…

Fix: after 2.4.7
Fix from $2,300 2018-01-18
Activemq MEDIUM 6.1
CVE-2016-6810EPSS 6%

In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administratio…

Fix: 5.14.2+
Fix from $1,600 2018-01-10
Sling Xss Protection Api MEDIUM 6.1
CVE-2017-15717

A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#i…

Fix: after 1.0.18
Fix from $1,600 2018-01-10
Geode HIGH 7.5
CVE-2017-9795

When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execut…

Fix: 1.3.0+
Fix from $1,950 2018-01-10
Geode HIGH 7.1
CVE-2017-12622

When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with…

Fix: 1.3.0+
Fix from $1,950 2018-01-10
Geode MEDIUM 5.3
CVE-2017-9796

When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execut…

Fix: 1.3.0+
Fix from $1,600 2018-01-10
Sling Jcr Contentloader HIGH 7.5
CVE-2012-3353

The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the con…

Mitigation only
Fix from $1,950 2018-01-09
Ofbiz CRITICAL 9.8
CVE-2017-15714

The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code …

No fix yet
Fix from $2,300 2018-01-04
Deltaspike MEDIUM 6.1
CVE-2017-17837

The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get's cut off after 10 cha…

Patch available
Fix from $1,600 2018-01-04
Flex Blazeds CRITICAL 9.8
CVE-2017-5641EPSS 21%

Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. …

Fix: 8.5.3-00+
Fix from $2,300 2017-12-28
Sling Authentication Service HIGH 8.8
CVE-2017-15700

A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the…

Mitigation only
Fix from $1,950 2017-12-18
Drill MEDIUM 5.4
CVE-2017-12630

In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Pro…

Fix: after 1.11.0
Fix from $1,600 2017-12-18
Fineract HIGH 8.8
CVE-2017-5663

In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissio…

Mitigation only
Fix from $1,950 2017-12-14
Synapse CRITICAL 9.8
CVE-2017-15708EPSS 18%

In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases…

Mitigation only
Fix from $2,300 2017-12-11
Struts MEDIUM 6.2
CVE-2017-15707

In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malici…

Fix: after 2.5.14
Fix from $1,600 2017-12-01
Qpid Broker J CRITICAL 9.8
CVE-2017-15702EPSS 6%

In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an …

Fix: after 0.32
Fix from $2,300 2017-12-01
Qpid Broker J HIGH 7.5
CVE-2017-15701

In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remo…

Fix: after 6.1.4
Fix from $1,950 2017-12-01
Cxf Fediz HIGH 8.8
CVE-2017-12631

Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) sty…

Fix: 1.3.3+
Fix from $1,950 2017-11-30
Openoffice HIGH 7.8
CVE-2017-12608

A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, allows attackers to craft malici…

Fix: 4.1.4+
Fix from $1,950 2017-11-20
Openoffice MEDIUM 5.5
CVE-2017-3157

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from …

Fix: after 4.1.3
Fix from $1,600 2017-11-20
Openoffice HIGH 7.8
CVE-2017-12607

A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, allows attackers to craft malicious documents that c…

Fix: 4.1.4+
Fix from $1,950 2017-11-20
Openoffice HIGH 7.8
CVE-2017-9806

A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and specifically in the WW8Fonts Constructor, allows attackers to craft malici…

Fix: 4.1.4+
Fix from $1,950 2017-11-20
Openoffice HIGH 7.8
CVE-2016-6804

The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operation that a…

Fix: 4.1.3+
Fix from $1,950 2017-11-20
Solr CRITICAL 9.1
CVE-2017-1000190

SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.

Fix: after 2.7.1
Fix from $2,300 2017-11-17
Karaf MEDIUM 5.5
CVE-2014-0219

Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sen…

Fix: 4.0.10+
Fix from $1,600 2017-11-15