Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Knox MEDIUM 6.8
CVE-2017-5646

For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing …

Mitigation only
Fix from $1,600 2017-05-26
Archiva HIGH 8.0
CVE-2017-5657

Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the …

Fix: after 2.2.1
Fix from $1,950 2017-05-22
Juddi MEDIUM 6.1
CVE-2015-5241

After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect…

Mitigation only
Fix from $1,600 2017-05-19
Cxf Fediz HIGH 8.8
CVE-2017-7661

Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) sty…

Fix: after 1.4.0
Fix from $1,950 2017-05-16
Cxf Fediz HIGH 8.8
CVE-2017-7662

Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application that allows c…

Fix: after 1.3.2
Fix from $1,950 2017-05-16
Qpid Broker J HIGH 7.5
CVE-2016-8741EPSS 6%

The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices…

Mitigation only
Fix from $1,950 2017-05-15
Ambari MEDIUM 6.5
CVE-2017-5655

In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary file…

Mitigation only
Fix from $1,600 2017-05-15
Ambari HIGH 7.5
CVE-2017-5654

In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on …

Mitigation only
Fix from $1,950 2017-05-12
Cordova HIGH 7.5
CVE-2016-6799

Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d()…

Fix: after 5.2.2
Fix from $1,950 2017-05-09
Qpid Proton MEDIUM 5.9
CVE-2016-4467

The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname m…

Mitigation only
Fix from $1,600 2017-05-02
Hadoop HIGH 7.3
CVE-2017-3162EPSS 6%

HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query parameter that is not validate…

Fix: after 2.6.5
Fix from $1,950 2017-04-26
Hadoop MEDIUM 6.1
CVE-2017-3161

The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter.

Fix: after 2.6.5
Fix from $1,600 2017-04-26
Cxf HIGH 7.5
CVE-2017-5656EPSS 7%

Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an a…

Fix: 3.0.13 / 3.1.11+
Fix from $1,950 2017-04-18
Cxf MEDIUM 5.3
CVE-2017-5653EPSS 11%

JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which…

Fix: after 3.1.11
Fix from $1,600 2017-04-18
Formatting Objects Processor HIGH 7.3
CVE-2017-5661

In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciously formed S…

Fix: after 2.1
Fix from $1,950 2017-04-18
Batik HIGH 7.3
CVE-2017-5662

In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously form…

Fix: after 1.8
Fix from $1,950 2017-04-18
Log4j CRITICAL 9.8
CVE-2017-5645EPSS 90%

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a …

Fix: 2.8.2+
Fix from $2,300 2017-04-17
Traffic Server HIGH 7.5
CVE-2016-5396

Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.

Patch available
Fix from $1,950 2017-04-17
Traffic Server HIGH 7.5
CVE-2017-5659

Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding.

Fix: after 6.2.0
Fix from $1,950 2017-04-17
Tomcat CRITICAL 9.8
CVE-2017-5651EPSS 8%

In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processin…

Patch available
Fix from $2,300 2017-04-17
Tomcat CRITICAL 9.1
CVE-2017-5648EPSS 13%

While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0…

Mitigation only
Fix from $2,300 2017-04-17
Tomcat HIGH 7.5
CVE-2017-5647EPSS 17%

A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.…

Mitigation only
Fix from $1,950 2017-04-17
Tomcat HIGH 7.5
CVE-2017-5650EPSS 8%

In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated …

Mitigation only
Fix from $1,950 2017-04-17
Tomcat Jk Connector CRITICAL 9.8
CVE-2016-6808EPSS 19%

Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.

Fix: 1.2.42+
Fix from $2,300 2017-04-12
Tomee CRITICAL 9.8
CVE-2016-0779EPSS 10%

The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted s…

Fix: after 1.7.3
Fix from $2,300 2017-04-11
Hadoop HIGH 8.8
CVE-2016-6811

In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.

Fix: after 2.7.3
Fix from $1,950 2017-04-11
Ignite MEDIUM 5.9
CVE-2016-6805

Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents.

Fix: after 1.8
Fix from $1,600 2017-04-07
Nutch CRITICAL 9.8
CVE-2016-6809EPSS 8%

Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to d…

Fix: after 1.13
Fix from $2,300 2017-04-06
Tomcat CRITICAL 9.8
CVE-2016-8735 KEVEPSS 90%

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M1…

Fix: 6.0.48 / 7.0.73+
Fix from $2,300 2017-04-06
Geode HIGH 7.5
CVE-2017-5649

Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUST…

Fix: after 1.1.0
Fix from $1,950 2017-04-04