Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openmeetings HIGH 7.5
CVE-2017-7684

Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded. An attacker can cause a denial of service by uploading multiple large files…

Mitigation only
Fix from $1,950 2017-07-17
Openmeetings MEDIUM 6.1
CVE-2017-7663

Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0.

Mitigation only
Fix from $1,600 2017-07-17
Wicket CRITICAL 9.1
CVE-2016-6793EPSS 8%

The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop…

Fix: 1.5.17 / 6.25.0+
Fix from $2,300 2017-07-17
Roller HIGH 7.2
CVE-2015-0249

The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary…

Mitigation only
Fix from $1,950 2017-07-17
HTTP Server CRITICAL 9.1
CVE-2017-9788EPSS 57%

In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or…

Fix: after 2.4.26
Fix from $2,300 2017-07-13
HTTP Server HIGH 7.5
CVE-2017-9789EPSS 10%

When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, r…

Mitigation only
Fix from $1,950 2017-07-13
Struts HIGH 7.5
CVE-2017-9787EPSS 11%

When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts versio…

Mitigation only
Fix from $1,950 2017-07-13
Struts MEDIUM 5.9
CVE-2017-7672EPSS 10%

If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used t…

Mitigation only
Fix from $1,600 2017-07-13
Spark MEDIUM 6.1
CVE-2017-7678

In Apache Spark before 2.2.0, it is possible for an attacker to take advantage of a user's trust in the server to trick them into visiting a link tha…

Fix: after 2.1.1
Fix from $1,600 2017-07-12
Impala CRITICAL 9.8
CVE-2017-5640

It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to ski…

Mitigation only
Fix from $2,300 2017-07-10
Impala HIGH 7.5
CVE-2017-5652

During a routine security analysis, it was found that one of the ports in Apache Impala (incubating) 2.7.0 to 2.8.0 sent data in plaintext even when …

Mitigation only
Fix from $1,950 2017-07-10
Traffic Control HIGH 7.5
CVE-2017-7670

The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TCP connec…

Fix: after 1.8.0
Fix from $1,950 2017-07-10
Struts CRITICAL 9.8
CVE-2017-9791 KEVEPSS 99%

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the Act…

Patch available
Fix from $2,300 2017-07-10
Solr HIGH 7.5
CVE-2017-7660EPSS 6%

Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node…

Mitigation only
Fix from $1,950 2017-07-07
Ignite HIGH 7.5
CVE-2017-7686

Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality…

Mitigation only
Fix from $1,950 2017-06-28
HTTP Server CRITICAL 9.8
CVE-2017-3167EPSS 20%

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication p…

Fix: 2.2.33 / 2.4.26+
Fix from $2,300 2017-06-20
HTTP Server CRITICAL 9.8
CVE-2017-3169EPSS 20%

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_con…

Mitigation only
Fix from $2,300 2017-06-20
HTTP Server CRITICAL 9.8
CVE-2017-7679EPSS 39%

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Typ…

Fix: 2.2.33 / 2.4.26+
Fix from $2,300 2017-06-20
HTTP Server HIGH 7.5
CVE-2017-7668EPSS 57%

The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to searc…

Patch available
Fix from $1,950 2017-06-20
Thrift MEDIUM 6.5
CVE-2015-3254EPSS 5%

The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vecto…

Fix: after 0.9.2
Fix from $1,600 2017-06-16
Ranger CRITICAL 9.8
CVE-2017-7676

Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in u…

Fix: after 0.7.0
Fix from $2,300 2017-06-14
Ranger MEDIUM 5.9
CVE-2016-8746

Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion fla…

Fix: after 0.6.2
Fix from $1,600 2017-06-14
Ranger MEDIUM 5.9
CVE-2017-7677

In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for creat…

Fix: after 0.7.0
Fix from $1,600 2017-06-14
Nifi HIGH 7.5
CVE-2017-7667

Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin.

Fix: after 0.7.3
Fix from $1,950 2017-06-12
Nifi MEDIUM 6.1
CVE-2017-7665

In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS iss…

Fix: after 0.7.3
Fix from $1,600 2017-06-12
Cxf Fediz HIGH 7.5
CVE-2015-5175EPSS 11%

Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service.

Fix: after 1.1.2
Fix from $1,950 2017-06-07
Ws Xmlrpc MEDIUM 6.5
CVE-2016-5004EPSS 6%

The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource …

No fix yet
Fix from $1,600 2017-06-06
Tomcat HIGH 7.5
CVE-2017-5664EPSS 17%

The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is configured for the error that occ…

Mitigation only
Fix from $1,950 2017-06-06
Hadoop HIGH 7.5
CVE-2017-7669

In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. W…

Mitigation only
Fix from $1,950 2017-06-05
Hive HIGH 7.5
CVE-2016-3083

Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the server's …

Mitigation only
Fix from $1,950 2017-05-30