Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HTTP Server MEDIUM 5.0
CVE-2015-0253EPSS 15%

The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows …

Patch available
Fix from $1,600 2015-07-20
Struts HIGH 7.5
CVE-2015-1831EPSS 6%

The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unsp…

Mitigation only
Fix from $1,950 2015-07-16
Tomcat HIGH 7.8
CVE-2014-0230EPSS 20%

Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishin…

Patch available
Fix from $1,950 2015-06-07
Camel MEDIUM 5.0
CVE-2015-0264EPSS 7%

Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remo…

Fix: after 2.13.3
Fix from $1,600 2015-06-03
Camel MEDIUM 5.0
CVE-2015-0263EPSS 8%

XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x befor…

Fix: after 2.13.3
Fix from $1,600 2015-06-03
Jackrabbit MEDIUM 6.4
CVE-2015-1833EPSS 51%

XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before …

Fix: after 2.0.5
Fix from $1,600 2015-05-29
Tomcat Connectors MEDIUM 5.0
CVE-2014-8111EPSS 7%

Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to acce…

Fix: after 1.2.40
Fix from $1,600 2015-04-21
Subversion MEDIUM 5.0
CVE-2015-0248EPSS 12%

The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of …

Mitigation only
Fix from $1,600 2015-04-08
Subversion HIGH 7.8
CVE-2015-0202EPSS 8%

The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large numbe…

Mitigation only
Fix from $1,950 2015-04-08
Cassandra HIGH 7.5
CVE-2015-0225EPSS 7%

The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI in…

No fix yet
Fix from $1,950 2015-04-03
Mod Gnutls MEDIUM 5.0
CVE-2015-2091

The authentication hook (mgs_hook_authz) in mod-gnutls 0.5.10 and earlier does not validate client certificates when "GnuTLSClientVerify require" is …

Fix: after 0.5.1
Fix from $1,600 2015-03-13
Standard Taglibs HIGH 7.5
CVE-2015-0254EPSS 13%

Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSL…

Fix: after 1.2.1
Fix from $1,950 2015-03-09
HTTP Server MEDIUM 5.0
CVE-2015-0228EPSS 19%

The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a de…

Fix: after 2.4.12
Fix from $1,600 2015-03-08
Tomcat MEDIUM 6.4
CVE-2014-0227EPSS 21%

java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not pr…

Mitigation only
Fix from $1,600 2015-02-16
Wss4j MEDIUM 5.0
CVE-2015-0227EPSS 8%

Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors …

Fix: after 1.6.16
Fix from $1,600 2015-02-12
Qpid MEDIUM 5.0
CVE-2015-0223EPSS 7%

Unspecified vulnerability in Apache Qpid 0.30 and earlier allows remote attackers to bypass access restrictions on qpidd via unknown vectors, related…

Fix: after 0.30
Fix from $1,600 2015-02-02
Santuario Xml Security For Java MEDIUM 5.0
CVE-2014-8152EPSS 6%

Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a cr…

Mitigation only
Fix from $1,600 2015-01-21
Cloudstack MEDIUM 5.0
CVE-2014-9593

Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.

Fix: after 4.3.1
Fix from $1,600 2015-01-15
Traffic Server MEDIUM 5.0
CVE-2014-10022EPSS 6%

Apache Traffic Server before 5.1.2 allows remote attackers to cause a denial of service via unspecified vectors, related to internal buffer sizing.

Fix: after 5.1.1
Fix from $1,600 2015-01-13
HTTP Server MEDIUM 5.0
CVE-2014-3583EPSS 11%

The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause …

Mitigation only
Fix from $1,600 2014-12-15
Struts MEDIUM 6.8
CVE-2014-7809

Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mecha…

No fix yet
Fix from $1,600 2014-12-10
Cloudstack MEDIUM 5.0
CVE-2014-7807

Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, …

Mitigation only
Fix from $1,600 2014-12-10
Hadoop MEDIUM 5.0
CVE-2014-3627

The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster u…

Mitigation only
Fix from $1,600 2014-12-05
Cordova MEDIUM 6.4
CVE-2014-3500

Apache Cordova Android before 3.5.1 allows remote attackers to change the start page via a crafted intent URL.

Fix: after 3.5.0
Fix from $1,600 2014-11-15
Cxf MEDIUM 5.0
CVE-2014-3584EPSS 7%

The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service …

Fix: after 2.6.10
Fix from $1,600 2014-10-30
Wss4j MEDIUM 5.0
CVE-2014-3623EPSS 9%

Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does …

Fix: 1.6.17 / 2.0.2+
Fix from $1,600 2014-10-30
HTTP Server MEDIUM 5.0
CVE-2014-3581EPSS 14%

The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote atta…

Patch available
Fix from $1,600 2014-10-10
Shiro HIGH 7.5
CVE-2014-0074EPSS 5%

Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an e…

No fix yet
Fix from $1,950 2014-10-06
Tomcat MEDIUM 6.8
CVE-2013-4444EPSS 14%

Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JM…

Fix: after 7.0.39
Fix from $1,600 2014-09-12
Axis MEDIUM 5.8
CVE-2014-3596EPSS 9%

The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Nam…

Fix: after 1.4
Fix from $1,600 2014-08-27