Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jetspeed HIGH 8.8
CVE-2016-0710EPSS 52%

Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL co…

Fix: after 2.3.0
Fix from $1,950 2016-04-11
Jetspeed HIGH 7.2
CVE-2016-0709EPSS 77%

Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticate…

Fix: after 2.3.0
Fix from $1,950 2016-04-11
Activemq MEDIUM 6.1
CVE-2016-0734EPSS 9%

The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for rem…

Mitigation only
Fix from $1,600 2016-04-07
Tomcat HIGH 8.8
CVE-2016-0714EPSS 13%

The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles s…

Mitigation only
Fix from $1,950 2016-02-25
Tomcat HIGH 8.8
CVE-2015-5351EPSS 10%

The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions a…

No fix yet
Fix from $1,950 2016-02-25
Tomcat HIGH 8.1
CVE-2015-5346EPSS 11%

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are us…

No fix yet
Fix from $1,950 2016-02-25
Solr MEDIUM 6.1
CVE-2015-8797

Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows rem…

Fix: after 5.3
Fix from $1,600 2016-02-15
Solr MEDIUM 6.1
CVE-2015-8796

Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers…

Fix: after 5.2.1
Fix from $1,600 2016-02-15
Solr MEDIUM 6.1
CVE-2015-8795

Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script o…

Fix: after 5.0
Fix from $1,600 2016-02-15
Sling HIGH 7.5
CVE-2016-0956EPSS 46%

The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sen…

Patch available
Fix from $1,950 2016-02-10
Cloudstack CRITICAL 9.8
CVE-2015-3252

Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain ac…

Fix: after 4.5.1
Fix from $2,300 2016-02-08
Camel CRITICAL 9.8
CVE-2015-5344EPSS 7%

The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted…

Fix: after 2.15.4
Fix from $2,300 2016-02-03
Hive HIGH 8.3
CVE-2015-7521EPSS 6%

The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, …

No fix yet
Fix from $1,950 2016-01-29
Subversion HIGH 8.6
CVE-2015-5259EPSS 57%

Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute ar…

Mitigation only
Fix from $1,950 2016-01-08
Hadoop HIGH 8.4
CVE-2015-7430

The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 before 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to…

Mitigation only
Fix from $1,950 2016-01-02
Hbase HIGH 7.3
CVE-2015-1836EPSS 7%

Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and o…

Mitigation only
Fix from $1,950 2015-12-21
Hive HIGH 7.3
CVE-2015-1772EPSS 7%

The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.…

Mitigation only
Fix from $1,950 2015-12-21
Commons Collections CRITICAL 9.8
CVE-2015-6420EPSS 18%

Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and…

Fix: 3.2.2+
Fix from $2,300 2015-12-15
Cordova MEDIUM 5.0
CVE-2015-8320

Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for attackers to conduct bridge h…

Fix: after 3.6.4
Fix from $1,600 2015-11-23
Openoffice MEDIUM 6.8
CVE-2015-5212EPSS 9%

Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the docu…

Fix: after 4.4.4
Fix from $1,600 2015-11-10
Ambari MEDIUM 5.8
CVE-2015-5210

Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attac…

Fix: after 2.1.1
Fix from $1,600 2015-11-02
Ambari MEDIUM 6.5
CVE-2015-3270

Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibl…

Mitigation only
Fix from $1,600 2015-11-02
Ambari MEDIUM 5.5
CVE-2015-1775

Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users…

Mitigation only
Fix from $1,600 2015-11-02
Activemq HIGH 7.5
CVE-2014-3612EPSS 7%

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote att…

Mitigation only
Fix from $1,950 2015-08-24
Tapestry HIGH 7.8
CVE-2014-1972EPSS 10%

Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attac…

Fix: after 5.3.5
Fix from $1,950 2015-08-22
Activemq MEDIUM 5.0
CVE-2015-1830EPSS 84%

Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows …

No fix yet
Fix from $1,600 2015-08-19
Activemq HIGH 7.5
CVE-2014-3576EPSS 13%

The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of s…

Fix: after 5.10.0
Fix from $1,950 2015-08-14
Groovy CRITICAL 9.8
CVE-2015-3253EPSS 41%

The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause…

Patch available
Fix from $2,300 2015-08-13
Subversion MEDIUM 5.0
CVE-2015-3184EPSS 11%

mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous a…

Fix: after 7.2.1
Fix from $1,600 2015-08-12
HTTP Server MEDIUM 5.0
CVE-2015-3183EPSS 73%

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attacke…

Fix: 2.2.31 / 2.4.16+
Fix from $1,600 2015-07-20