Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tomcat MEDIUM 5.0
CVE-2012-2733EPSS 9%

java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not…

Mitigation only
Fix from $1,600 2012-11-16
Libcloud MEDIUM 5.9
CVE-2012-3446

Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the su…

Fix: 0.11.0+
Fix from $1,600 2012-11-04
Httpclient MEDIUM 5.8
CVE-2012-5783EPSS 9%

Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the serve…

Patch available
Fix from $1,600 2012-11-04
Activemq MEDIUM 5.8
CVE-2012-5784EPSS 6%

Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service impleme…

Fix: after 5.7.0
Fix from $1,600 2012-11-04
Axis2 MEDIUM 5.8
CVE-2012-5785

Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…

Fix: after 1.6.2
Fix from $1,600 2012-11-04
Cxf MEDIUM 5.8
CVE-2012-5786

The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that …

Fix: after 2.6.17
Fix from $1,600 2012-11-04
Cloudstack HIGH 10.0
CVE-2012-4501EPSS 8%

Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user acc…

Mitigation only
Fix from $1,950 2012-10-26
Ofbiz HIGH 10.0
CVE-2012-3506EPSS 7%

Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.

Patch available
Fix from $1,950 2012-10-25
Axis2 MEDIUM 6.4
CVE-2012-5351EPSS 5%

Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signatur…

Mitigation only
Fix from $1,600 2012-10-09
Axis2 MEDIUM 5.8
CVE-2012-4418EPSS 6%

Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."

No fix yet
Fix from $1,600 2012-10-09
Qpid MEDIUM 5.0
CVE-2012-2145

Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file…

Fix: after 0.17
Fix from $1,600 2012-09-28
Struts MEDIUM 6.8
CVE-2012-4386

The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote…

Mitigation only
Fix from $1,600 2012-09-05
Struts MEDIUM 5.0
CVE-2012-4387EPSS 8%

Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processe…

Patch available
Fix from $1,600 2012-09-05
Qpid MEDIUM 5.0
CVE-2012-3467EPSS 6%

Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remo…

Fix: after 0.16
Fix from $1,600 2012-08-27
Poi MEDIUM 5.0
CVE-2012-0213EPSS 8%

The UnhandledDataStructure function in hwpf/model/UnhandledDataStructure.java in Apache POI 3.8 and earlier allows remote attackers to cause a denial…

Fix: after 3.8
Fix from $1,600 2012-08-07
Openoffice HIGH 7.5
CVE-2012-2665EPSS 7%

Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow re…

Fix: 3.4.1+
Fix from $1,950 2012-08-06
Hadoop HIGH 7.5
CVE-2012-3376

DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same B…

Mitigation only
Fix from $1,950 2012-07-12
Org.apache.sling.servlets.post MEDIUM 5.0
CVE-2012-2138EPSS 14%

The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to co…

Fix: after 2.1.0
Fix from $1,600 2012-07-09
Commons Compress MEDIUM 5.0
CVE-2012-2098EPSS 13%

Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress b…

Fix: 1.4.1+
Fix from $1,600 2012-06-29
Roller MEDIUM 6.8
CVE-2012-2380

Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack…

Fix: after 5.0
Fix from $1,600 2012-06-26
Openoffice.org MEDIUM 6.8
CVE-2012-2334EPSS 13%

Integer overflow in filter/source/msfilter/msdffimp.cxx in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, al…

Fix: after 3.5.2
Fix from $1,600 2012-06-19
Openoffice MEDIUM 6.5
CVE-2012-0037EPSS 14%

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other produ…

Patch available
Fix from $1,600 2012-06-17
Qpid HIGH 7.5
CVE-2011-3620EPSS 5%

Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messagin…

Mitigation only
Fix from $1,950 2012-05-03
HTTP Server MEDIUM 6.9
CVE-2012-0883

envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users…

Fix: 2.2.23+
Fix from $1,600 2012-04-18
Hadoop MEDIUM 6.5
CVE-2012-1574

The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used i…

Mitigation only
Fix from $1,600 2012-04-12
Traffic Server MEDIUM 5.0
CVE-2012-0256

Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to ca…

Patch available
Fix from $1,600 2012-03-26
Wicket MEDIUM 5.0
CVE-2012-1089EPSS 5%

Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-applicati…

Mitigation only
Fix from $1,600 2012-03-23
Mod Fcgid MEDIUM 5.0
CVE-2012-1181

fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual h…

Patch available
Fix from $1,600 2012-03-19
Struts HIGH 10.0
CVE-2012-0838EPSS 14%

Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to m…

Fix: after 2.2.3
Fix from $1,950 2012-03-02
Portable Runtime MEDIUM 5.0
CVE-2012-0840EPSS 43%

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash col…

Fix: after 1.4.5
Fix from $1,600 2012-02-10