Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cordova HIGH 7.5
CVE-2014-1881EPSS 11%

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an ev…

Fix: after 3.3.0
Fix from $1,950 2014-03-03
Cordova HIGH 7.5
CVE-2014-1882EPSS 12%

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an ev…

Fix: after 3.3.0
Fix from $1,950 2014-03-03
Cordova HIGH 7.5
CVE-2014-1884EPSS 8%

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier on Windows Phone 7 and 8 do not properly restrict navigation events, which allo…

Fix: after 3.3.0
Fix from $1,950 2014-03-03
Tomcat MEDIUM 5.8
CVE-2013-4286EPSS 17%

Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle c…

Mitigation only
Fix from $1,600 2014-02-26
Wicket MEDIUM 5.0
CVE-2013-2055

Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive…

Mitigation only
Fix from $1,600 2014-02-10
Tomcat HIGH 7.5
CVE-2013-2185EPSS 7%

The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Re…

Fix: after 7.0.39
Fix from $1,950 2014-01-19
Solr HIGH 7.5
CVE-2012-6612EPSS 10%

The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via…

Fix: after 4.0.0
Fix from $1,950 2013-12-07
Roller MEDIUM 6.8
CVE-2013-4212EPSS 81%

Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions vi…

Fix: after 5.0.1
Fix from $1,600 2013-12-07
Solr MEDIUM 6.4
CVE-2013-6407EPSS 11%

The UpdateRequestHandler for XML in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external …

Fix: after 4.0.0
Fix from $1,600 2013-12-07
Solr MEDIUM 6.4
CVE-2013-6408EPSS 11%

The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have a…

Fix: after 4.3.0
Fix from $1,600 2013-12-07
Tomcat MEDIUM 6.8
CVE-2013-6357

Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the …

Fix: after 5.5.25
Fix from $1,600 2013-11-13
Sling MEDIUM 5.8
CVE-2013-4390

Open redirect vulnerability in the AbstractAuthenticationFormServlet in the Auth Core (org.apache.sling.auth.core) bundle before 1.1.4 in Apache Slin…

Fix: after 1.1.2
Fix from $1,600 2013-10-24
Shindig MEDIUM 5.0
CVE-2013-4295EPSS 12%

The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing an externa…

Patch available
Fix from $1,600 2013-10-24
Mod Fcgid HIGH 7.5
CVE-2013-4365EPSS 13%

Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server…

Fix: 2.3.9+
Fix from $1,950 2013-10-17
Org.apache.sling.servlets.post MEDIUM 5.0
CVE-2013-2254

The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache S…

Patch available
Fix from $1,600 2013-10-17
Camel MEDIUM 6.8
CVE-2013-4330EPSS 9%

Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expres…

Fix: after 2.9.6
Fix from $1,600 2013-10-04
Struts HIGH 10.0
CVE-2013-4316EPSS 8%

Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.

Fix: after 3.0.4
Fix from $1,950 2013-09-30
Struts MEDIUM 5.8
CVE-2013-4310EPSS 8%

Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.

Patch available
Fix from $1,600 2013-09-30
Xml Security For C\+\+ HIGH 7.5
CVE-2013-2210EPSS 6%

Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.2 al…

Fix: after 1.7.1
Fix from $1,950 2013-08-20
Xml Security For C\+\+ HIGH 7.5
CVE-2013-2154EPSS 8%

Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka …

Fix: after 1.7.0
Fix from $1,950 2013-08-20
Xml Security For C\+\+ HIGH 7.5
CVE-2013-2156EPSS 8%

Heap-based buffer overflow in the Exclusive Canonicalization functionality (xsec/canon/XSECC14n20010315.cpp) in Apache Santuario XML Security for C++…

Fix: after 1.7.0
Fix from $1,950 2013-08-20
Xml Security For C\+\+ MEDIUM 5.8
CVE-2013-2155EPSS 6%

Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to ca…

Fix: after 1.7.0
Fix from $1,600 2013-08-20
Cxf MEDIUM 6.4
CVE-2012-5575EPSS 6%

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowe…

Mitigation only
Fix from $1,600 2013-08-19
Cxf MEDIUM 5.0
CVE-2013-2160EPSS 32%

The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of s…

Patch available
Fix from $1,600 2013-08-19
Ofbiz HIGH 10.0
CVE-2013-2250EPSS 12%

Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute ar…

Patch available
Fix from $1,950 2013-08-15
Openoffice MEDIUM 6.8
CVE-2013-4156

Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other im…

Fix: 4.0.0+
Fix from $1,600 2013-07-31
Openoffice MEDIUM 6.8
CVE-2013-2189

Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other im…

Fix: 4.0.0+
Fix from $1,600 2013-07-31
Subversion HIGH 7.8
CVE-2013-2112

The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a con…

Fix: after 1.6.21
Fix from $1,950 2013-07-31
Subversion HIGH 7.1
CVE-2013-2088EPSS 31%

contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary …

Fix: after 1.6.21
Fix from $1,950 2013-07-31
Subversion MEDIUM 5.5
CVE-2013-1968

Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a ne…

Fix: after 1.6.21
Fix from $1,600 2013-07-31