Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Camel CRITICAL 9.8
CVE-2017-12633EPSS 7%

The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. D…

Fix: 2.19.4 / 2.20.1+
Fix from $2,300 2017-11-15
Camel CRITICAL 9.8
CVE-2017-12634EPSS 7%

The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De…

Fix: 2.19.4+
Fix from $2,300 2017-11-15
Couchdb CRITICAL 9.8
CVE-2017-12635EPSS 100%

Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1…

Fix: 1.7.0+
Fix from $2,300 2017-11-14
Couchdb HIGH 7.2
CVE-2017-12636EPSS 90%

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-leve…

Fix: 1.7.0+
Fix from $1,950 2017-11-14
Cxf MEDIUM 5.5
CVE-2017-12624

Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment he…

Fix: 3.0.16 / 3.1.14+
Fix from $1,600 2017-11-14
Openoffice HIGH 7.8
CVE-2016-6803

An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3 installers for Windows. The …

Fix: after 4.1.2
Fix from $1,950 2017-11-13
Hadoop HIGH 7.8
CVE-2017-3166

In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it worl…

Mitigation only
Fix from $1,950 2017-11-13
Hadoop CRITICAL 9.8
CVE-2012-4449

Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features ar…

Fix: after 0.23.3
Fix from $2,300 2017-10-30
Httpclient CRITICAL 9.8
CVE-2013-4366

http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows a…

Patch available
Fix from $2,300 2017-10-30
Cordova In App Browser CRITICAL 9.8
CVE-2014-0073EPSS 8%

The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-Ap…

Fix: after 2.9.0
Fix from $2,300 2017-10-30
Cordova File Transfer HIGH 7.5
CVE-2014-0072EPSS 8%

ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.4.2 for iOS and the File-Tran…

Fix: after 2.9.0
Fix from $1,950 2017-10-30
Wicket MEDIUM 6.1
CVE-2012-5636

Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers…

Patch available
Fix from $1,600 2017-10-30
Xerces2 Java HIGH 7.5
CVE-2012-0881EPSS 17%

Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML servi…

Fix: after 2.11.0
Fix from $1,950 2017-10-30
Storm HIGH 7.5
CVE-2014-0115EPSS 5%

Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the…

Patch available
Fix from $1,950 2017-10-30
Juddi MEDIUM 6.1
CVE-2009-1198

Cross-site scripting (XSS) vulnerability in Apache jUDDI before 2.0 allows remote attackers to inject arbitrary web script or HTML via the dsname par…

Fix: 2.0+
Fix from $1,600 2017-10-30
Juddi MEDIUM 5.3
CVE-2009-1197

Apache jUDDI before 2.0 allows attackers to spoof entries in log files via vectors related to error logging of keys from uddiget.jsp.

Mitigation only
Fix from $1,600 2017-10-30
Traffic Server CRITICAL 9.8
CVE-2014-3624

Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap request…

Patch available
Fix from $2,300 2017-10-30
Traffic Server CRITICAL 9.8
CVE-2015-3249EPSS 5%

The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds acces…

Mitigation only
Fix from $2,300 2017-10-30
Subversion HIGH 8.8
CVE-2013-4246

libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories a…

Patch available
Fix from $1,950 2017-10-30
Struts HIGH 8.8
CVE-2016-3090EPSS 6%

The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL e…

Mitigation only
Fix from $1,950 2017-10-30
Wicket HIGH 7.5
CVE-2014-3526

Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors invo…

Fix: 1.5.12+
Fix from $1,950 2017-10-30
Qpid HIGH 7.5
CVE-2015-0224EPSS 15%

qpidd in Apache Qpid 0.30 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted protocol sequence set. NOTE:…

Fix: after 0.30
Fix from $1,950 2017-10-30
Wss4j HIGH 7.5
CVE-2015-0226EPSS 6%

Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message …

Fix: after 1.6.16
Fix from $1,950 2017-10-30
Activemq Apollo CRITICAL 9.8
CVE-2014-3579

XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors inv…

Mitigation only
Fix from $2,300 2017-10-27
Activemq CRITICAL 9.8
CVE-2014-3600EPSS 10%

XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving…

Mitigation only
Fix from $2,300 2017-10-27
Cordova MEDIUM 5.3
CVE-2015-1835EPSS 6%

Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to …

Fix: after 3.7.1
Fix from $1,600 2017-10-27
Ws Xmlrpc CRITICAL 9.8
CVE-2016-5003EPSS 15%

The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serializ…

No fix yet
Fix from $2,300 2017-10-27
Xml Rpc HIGH 7.8
CVE-2016-5002EPSS 8%

XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to co…

Mitigation only
Fix from $1,950 2017-10-27
Ofbiz CRITICAL 9.8
CVE-2012-1622EPSS 5%

Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.

Mitigation only
Fix from $2,300 2017-10-26
Portable Runtime HIGH 7.1
CVE-2017-12613

When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, ou…

Fix: 1.7.0+
Fix from $1,950 2017-10-24