Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openoffice HIGH 9.3
CVE-2014-3524EPSS 15%

Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc sp…

Fix: 4.1.1 / 4.2.6+
Fix from $1,950 2014-08-26
Traffic Server HIGH 10.0
CVE-2014-3525

Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors,…

No fix yet
Fix from $1,950 2014-08-22
Httpclient MEDIUM 5.8
CVE-2014-3577EPSS 9%

org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify …

Fix: after 4.3.4
Fix from $1,600 2014-08-21
HTTP Server MEDIUM 5.0
CVE-2014-3523EPSS 16%

Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x before 2.4.10 on Windows, when …

Patch available
Fix from $1,600 2014-07-20
HTTP Server MEDIUM 6.8
CVE-2014-0226EPSS 86%

Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buff…

Fix: 2.2.29 / 2.4.10+
Fix from $1,600 2014-07-20
HTTP Server MEDIUM 5.0
CVE-2014-0231EPSS 44%

The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of ser…

Fix: 2.2.29 / 2.4.10+
Fix from $1,600 2014-07-20
Syncope MEDIUM 5.0
CVE-2014-3503EPSS 6%

Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via…

No fix yet
Fix from $1,600 2014-07-11
Myfaces MEDIUM 5.0
CVE-2011-4367EPSS 33%

Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allo…

Fix: after 2.1.5
Fix from $1,600 2014-06-19
Tomcat MEDIUM 5.0
CVE-2014-0075EPSS 20%

Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6.0.40, 7.…

Mitigation only
Fix from $1,600 2014-05-31
Tomcat MEDIUM 5.0
CVE-2014-0095EPSS 8%

java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread c…

Patch available
Fix from $1,600 2014-05-31
Cloudstack MEDIUM 5.0
CVE-2013-2758EPSS 6%

Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable se…

Patch available
Fix from $1,600 2014-05-23
Cloudstack MEDIUM 5.0
CVE-2013-2756EPSS 6%

Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypa…

Patch available
Fix from $1,600 2014-05-23
Couchdb MEDIUM 6.8
CVE-2012-5649EPSS 7%

Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to execute arbitrary code via a JSONP callback, relat…

Fix: after 1.0.3
Fix from $1,600 2014-05-23
Struts MEDIUM 5.8
CVE-2014-0116EPSS 7%

CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass me…

Mitigation only
Fix from $1,600 2014-05-08
Commons Beanutils HIGH 7.5
CVE-2014-0114EPSS 96%

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commo…

Fix: after 1.9.1
Fix from $1,950 2014-04-30
Harmony MEDIUM 5.0
CVE-2013-7372

The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/crypto/SHA1PRNG_SecureRandomImpl.…

Fix: after 6.0
Fix from $1,600 2014-04-29
Struts HIGH 7.5
CVE-2014-0112EPSS 98%

ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "mani…

Fix: 2.3.16.2+
Fix from $1,950 2014-04-29
Struts HIGH 7.5
CVE-2014-0113EPSS 78%

CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method…

Fix: 2.3.16.2+
Fix from $1,950 2014-04-29
Syncope MEDIUM 6.5
CVE-2014-0111

Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Co…

Fix: 1.0.9 / 1.1.7+
Fix from $1,600 2014-04-17
Xalan Java HIGH 7.5
CVE-2014-0107EPSS 14%

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is en…

Fix: after 2.7.1
Fix from $1,950 2014-04-15
HTTP Server MEDIUM 5.0
CVE-2013-5704EPSS 60%

The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the…

Patch available
Fix from $1,600 2014-04-15
Commons Fileupload HIGH 7.5
CVE-2014-0050EPSS 83%

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to c…

Fix: after 1.3
Fix from $1,950 2014-04-01
Couchdb MEDIUM 5.0
CVE-2014-2668EPSS 22%

Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via the count parameter to /_uuids.

Fix: after 1.5.0
Fix from $1,600 2014-03-28
Camel HIGH 7.5
CVE-2014-0002EPSS 33%

The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other uns…

Fix: after 2.11.3
Fix from $1,950 2014-03-21
Camel HIGH 7.5
CVE-2014-0003EPSS 7%

The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbit…

Fix: after 2.11.3
Fix from $1,950 2014-03-21
Couchdb MEDIUM 5.0
CVE-2012-5641EPSS 9%

Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1…

Fix: after 2.3.2
Fix from $1,600 2014-03-18
HTTP Server MEDIUM 5.0
CVE-2013-6438EPSS 27%

The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace charac…

Fix: 2.2.27 / 2.4.9+
Fix from $1,600 2014-03-18
HTTP Server MEDIUM 5.0
CVE-2014-0098EPSS 26%

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a de…

Fix: 2.2.27 / 2.4.9+
Fix from $1,600 2014-03-18
Struts MEDIUM 5.0
CVE-2014-0094EPSS 100%

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is …

Fix: 2.3.16.1+
Fix from $1,600 2014-03-11
Cordova HIGH 7.5
CVE-2012-6637EPSS 9%

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote a…

Fix: after 3.3.0
Fix from $1,950 2014-03-03