Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tomcat HIGH 7.5
CVE-2017-12616EPSS 71%

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs …

Mitigation only
Fix from $1,950 2017-09-19
Solr HIGH 7.5
CVE-2017-9803

Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or a…

Mitigation only
Fix from $1,950 2017-09-18
HTTP Server HIGH 7.5
CVE-2017-9798EPSS 95%

Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if http…

Fix: after 2.2.34
Fix from $1,950 2017-09-18
Wicket HIGH 7.5
CVE-2014-7808

Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism a…

Fix: 1.5.13 / 6.19.0+
Fix from $1,950 2017-09-15
Struts HIGH 8.1
CVE-2017-9805 KEVEPSS 99%

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for des…

Fix: 2.3.34 / 2.5.13+
Fix from $1,950 2017-09-15
Traffic Server CRITICAL 9.8
CVE-2015-5168

Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a dif…

No fix yet
Fix from $2,300 2017-09-13
Traffic Server CRITICAL 9.8
CVE-2015-5206

Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unknown impact and attack vectors…

Mitigation only
Fix from $2,300 2017-09-13
Brooklyn HIGH 8.8
CVE-2016-8737

In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site request forgery (CSRF), which could permit a malicious web site to prod…

Fix: after 0.9.0
Fix from $1,950 2017-09-13
Brooklyn HIGH 8.8
CVE-2016-8744

Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate that SnakeYAML should unmarshal…

Fix: after 0.9.0
Fix from $1,950 2017-09-13
Spark HIGH 7.8
CVE-2017-12612

In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched …

Mitigation only
Fix from $1,950 2017-09-13
Brooklyn MEDIUM 5.4
CVE-2017-3165

In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site scripting where one authenticated user can cause scripts to run in the …

Fix: after 0.9.0
Fix from $1,600 2017-09-13
Directory Ldap Api HIGH 7.5
CVE-2015-3250EPSS 5%

Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.

Fix: after 1.0.0
Fix from $1,950 2017-09-07
Hadoop CRITICAL 9.8
CVE-2016-3086

The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeM…

Mitigation only
Fix from $2,300 2017-09-05
Hadoop MEDIUM 5.5
CVE-2016-5001

This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A lo…

Fix: after 2.6.3
Fix from $1,600 2017-08-30
Ofbiz HIGH 8.8
CVE-2016-4462

By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that ar…

Mitigation only
Fix from $1,950 2017-08-30
Ofbiz MEDIUM 6.1
CVE-2016-6800

The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to s…

Mitigation only
Fix from $1,600 2017-08-30
Solr HIGH 7.5
CVE-2017-3163EPSS 7%

When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file nam…

Fix: after 5.5.3
Fix from $1,950 2017-08-30
Atlas HIGH 7.5
CVE-2016-8752

Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URI…

Mitigation only
Fix from $1,950 2017-08-29
Atlas HIGH 7.5
CVE-2017-3154

Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.

Mitigation only
Fix from $1,950 2017-08-29
Atlas MEDIUM 6.1
CVE-2017-3150

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script.

Mitigation only
Fix from $1,600 2017-08-29
Atlas MEDIUM 6.1
CVE-2017-3151

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality.

Mitigation only
Fix from $1,600 2017-08-29
Atlas MEDIUM 6.1
CVE-2017-3152

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.

Mitigation only
Fix from $1,600 2017-08-29
Atlas MEDIUM 6.1
CVE-2017-3153

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality.

Mitigation only
Fix from $1,600 2017-08-29
Atlas MEDIUM 6.1
CVE-2017-3155

Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting.

Mitigation only
Fix from $1,600 2017-08-29
Struts HIGH 7.5
CVE-2015-5209EPSS 9%

Apache Struts 2.x before 2.3.24.1 allows remote attackers to manipulate Struts internals, alter user sessions, or affect container settings via vecto…

Mitigation only
Fix from $1,950 2017-08-29
Pony Mail CRITICAL 9.8
CVE-2016-4460EPSS 6%

Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.

Patch available
Fix from $2,300 2017-08-22
Sling Servlets Post MEDIUM 6.1
CVE-2017-9802

The Javascript method Sling.evalString() in Apache Sling Servlets Post before 2.3.22 uses the javascript 'eval' function to parse input strings, whic…

Fix: after 2.3.20
Fix from $1,600 2017-08-14
Subversion CRITICAL 9.8
CVE-2017-9800EPSS 19%

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run …

Fix: after 1.8.18
Fix from $2,300 2017-08-11
Tomcat HIGH 7.5
CVE-2016-6796EPSS 8%

A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 w…

Fix: after 8.5.4
Fix from $1,950 2017-08-11
Tomcat HIGH 7.5
CVE-2017-7675EPSS 10%

The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory tr…

Mitigation only
Fix from $1,950 2017-08-11