Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tomcat HIGH 7.5
CVE-2016-6797EPSS 8%

The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.4…

Fix: after 8.5.4
Fix from $1,950 2017-08-10
Tomcat HIGH 7.5
CVE-2016-6817EPSS 7%

The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger …

Mitigation only
Fix from $1,950 2017-08-10
Tomcat HIGH 7.5
CVE-2016-8745EPSS 16%

A bug in the error handling of the send file code for the NIO HTTP connector in Apache Tomcat 9.0.0.M1 to 9.0.0.M13, 8.5.0 to 8.5.8, 8.0.0.RC1 to 8.0…

Mitigation only
Fix from $1,950 2017-08-10
Cxf HIGH 7.5
CVE-2016-8739EPSS 7%

The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apach…

Fix: after 3.0.11
Fix from $1,950 2017-08-10
Cxf HIGH 7.5
CVE-2017-3156EPSS 6%

The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature compa…

Fix: after 3.0.12
Fix from $1,950 2017-08-10
Tomcat CRITICAL 9.1
CVE-2016-5018EPSS 10%

In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able …

Fix: after 8.5.4
Fix from $2,300 2017-08-10
Cxf MEDIUM 6.1
CVE-2016-6812EPSS 9%

The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists …

Fix: after 3.0.11
Fix from $1,600 2017-08-10
Tomcat MEDIUM 5.9
CVE-2016-0762EPSS 8%

The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 di…

Fix: after 8.5.4
Fix from $1,600 2017-08-10
Tomcat MEDIUM 5.3
CVE-2016-6794EPSS 7%

When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache To…

Fix: after 8.5.4
Fix from $1,600 2017-08-10
Storm HIGH 8.8
CVE-2017-9799

It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for …

Mitigation only
Fix from $1,950 2017-08-09
Cxf CRITICAL 9.8
CVE-2012-0803

The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as pa…

Patch available
Fix from $2,300 2017-08-08
Myfaces HIGH 7.5
CVE-2011-4343EPSS 5%

Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL express…

Patch available
Fix from $1,950 2017-08-08
Xerces C\+\+ HIGH 7.5
CVE-2012-0880

Apache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes has…

Mitigation only
Fix from $1,950 2017-08-08
Wink HIGH 7.4
CVE-2010-2245EPSS 12%

XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service…

Fix: after 1.1.1
Fix from $1,950 2017-08-08
Commons Email HIGH 7.5
CVE-2017-9801EPSS 6%

When a call-site passes a subject for an email that contains line-breaks in Apache Commons Email 1.0 through 1.4, the caller can add arbitrary SMTP h…

Mitigation only
Fix from $1,950 2017-08-07
HTTP Server HIGH 7.5
CVE-2016-0736EPSS 49%

In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either C…

No fix yet
Fix from $1,950 2017-07-27
HTTP Server HIGH 7.5
CVE-2016-2161EPSS 21%

In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to cras…

Mitigation only
Fix from $1,950 2017-07-27
HTTP Server HIGH 7.5
CVE-2016-8743EPSS 13%

Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and h…

Fix: after 2.4.23
Fix from $1,950 2017-07-27
HTTP Server HIGH 7.5
CVE-2017-7659EPSS 54%

A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash the serve…

Mitigation only
Fix from $1,950 2017-07-26
Sling CRITICAL 9.8
CVE-2016-6798

In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string…

Fix: after 1.0.10
Fix from $2,300 2017-07-19
Sling MEDIUM 6.1
CVE-2016-5394

In the XSS Protection API module before 1.0.12 in Apache Sling, the encoding done by the XSSAPI.encodeForJSString() method is not restrictive enough …

Fix: 1.0.12+
Fix from $1,600 2017-07-19
Openmeetings HIGH 7.5
CVE-2017-7688

Apache OpenMeetings 1.0.0 updates user password in insecure manner.

No fix yet
Fix from $1,950 2017-07-17
Openmeetings MEDIUM 5.3
CVE-2017-7685

Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH.

Mitigation only
Fix from $1,600 2017-07-17
Openmeetings CRITICAL 10.0
CVE-2017-7664

Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.

Mitigation only
Fix from $2,300 2017-07-17
Openmeetings CRITICAL 9.8
CVE-2017-7673

Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms …

Mitigation only
Fix from $2,300 2017-07-17
Openmeetings HIGH 8.8
CVE-2017-7666

Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.

Mitigation only
Fix from $1,950 2017-07-17
Openmeetings HIGH 8.8
CVE-2017-7681

Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the …

Mitigation only
Fix from $1,950 2017-07-17
Openmeetings HIGH 8.2
CVE-2017-7682

Apache OpenMeetings 3.2.0 is vulnerable to parameter manipulation attacks, as a result attacker has access to restricted areas.

Mitigation only
Fix from $1,950 2017-07-17
Openmeetings HIGH 7.5
CVE-2017-7680

Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file. This allows for flash content to be loaded from untrusted domains.

Mitigation only
Fix from $1,950 2017-07-17
Openmeetings HIGH 7.5
CVE-2017-7683

Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure.

Mitigation only
Fix from $1,950 2017-07-17