Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-17571EPSS 69% Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbi… Log4j 4.14.3+ Fix from $2,3002019-12-20 HIGH 8.1 CVE-2018-1311EPSS 10% The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been … Xerces C\+\+ 3.2.5+ Fix from $1,9502019-12-18 MEDIUM 5.3 CVE-2019-12413 In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access to, by using a specially cra… Superset 0.31+ Fix from $1,6002019-12-16 MEDIUM 5.3 CVE-2019-12414 In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in SQLLab Superset 0.32+ Fix from $1,6002019-12-16 HIGH 7.5 CVE-2014-0212 qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors Qpid Cpp Mitigation only Fix from $1,9502019-12-13 HIGH 7.5 CVE-2019-12420EPSS 7% In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the r… Spamassassin 3.4.3+ Fix from $1,9502019-12-12 MEDIUM 6.7 CVE-2018-11805 In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits ca… Spamassassin 3.4.3+ Fix from $1,6002019-12-12 HIGH 8.8 CVE-2012-1592EPSS 29% A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbit… Struts Mitigation only Fix from $1,9502019-12-05 HIGH 7.5 CVE-2019-17555 The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method w… Olingo after 4.6.0 Fix from $1,9502019-12-04 CRITICAL 9.8 CVE-2019-17556 Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being … Olingo after 4.6.0 Fix from $2,3002019-12-04 MEDIUM 5.5 CVE-2019-17554EPSS 12% The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Requ… Olingo after 4.6.0 Fix from $1,6002019-12-04 HIGH 8.8 CVE-2016-1000104 A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07. Mod Fcgid after 2016-07-07 Fix from $1,9502019-12-03 HIGH 7.8 CVE-2011-2177 OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the OpenOffice.org suite tools. Openoffice Mitigation only Fix from $1,9502019-11-27 HIGH 7.5 CVE-2011-3600EPSS 16% The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with exe… Ofbiz after 16.11.04 Fix from $1,9502019-11-26 HIGH 8.8 CVE-2019-12421 When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi versions 1.0.0 to 1.9.2, NiFi invalidates the authenticat… Nifi after 1.9.2 Fix from $1,9502019-11-19 MEDIUM 6.5 CVE-2019-10080 The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML f… Nifi after 1.9.2 Fix from $1,6002019-11-19 MEDIUM 5.3 CVE-2019-10083 When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most … Nifi after 1.9.2 Fix from $1,6002019-11-19 HIGH 7.5 CVE-2019-12422EPSS 9% Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding attack. Shiro 1.4.2+ Fix from $1,9502019-11-18 CRITICAL 9.8 CVE-2019-12409EPSS 22% The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh… Solr No fix yet Fix from $2,3002019-11-18 MEDIUM 6.1 CVE-2019-10070 Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality Atlas Mitigation only Fix from $1,6002019-11-18 MEDIUM 6.5 CVE-2009-5004 qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use . Qpid Cpp Mitigation only Fix from $1,6002019-11-09 HIGH 7.5 CVE-2019-12408 It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had a uniniti… Arrow after 0.14.1 Fix from $1,9502019-11-08 HIGH 7.5 CVE-2019-12410 While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory A… Arrow after 0.14.1 Fix from $1,9502019-11-08 CRITICAL 9.8 CVE-2019-12419EPSS 14% Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulne… Cxf 3.2.11 / 3.3.4+ Fix from $2,3002019-11-06 MEDIUM 6.5 CVE-2019-12406EPSS 6% Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility o… Cxf 3.2.11 / 3.3.4+ Fix from $1,6002019-11-06 HIGH 7.5 CVE-2019-10084 In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions o… Impala after 3.2.0 Fix from $1,9502019-11-05 CRITICAL 9.8 CVE-2011-3923EPSS 89% Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. Struts 2.3.1.2+ Fix from $2,3002019-11-01 HIGH 7.5 CVE-2019-0205EPSS 9% In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because… Thrift after 0.12.0 Fix from $1,9502019-10-29 HIGH 7.5 CVE-2019-0210EPSS 7% In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data. Thrift after 0.12.0 Fix from $1,9502019-10-29 HIGH 7.5 CVE-2012-2945 Hadoop 1.0.3 contains a symlink vulnerability. Hadoop No fix yet Fix from $1,9502019-10-29