Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2018-8015 In Apache ORC 1.0.0 to 1.4.3 a malformed ORC file can trigger an endlessly recursive function call in the C++ or Java parser. The impact of this bug … Orc after 1.4.3 Fix from $1,9502018-05-18 CRITICAL 9.8 CVE-2018-8014EPSS 22% The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are ins… Tomcat after 9.0.8 Fix from $2,3002018-05-16 MEDIUM 5.3 CVE-2018-1313 In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a database whose lo… Derby after 10.14.1.0 Fix from $1,6002018-05-07 MEDIUM 5.3 CVE-2018-8003 Apache Ambari, versions 1.4.0 to 2.6.1, is susceptible to a directory traversal attack allowing an unauthenticated user to craft an HTTP request whic… Ambari after 2.6.1 Fix from $1,6002018-05-03 HIGH 7.5 CVE-2018-10583EPSS 79% An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB co… Openoffice No fix yet Fix from $1,9502018-05-01 MEDIUM 6.5 CVE-2017-15691EPSS 9% In Apache uimaj prior to 2.10.2, Apache uimaj 3.0.0-xxx prior to 3.0.0-beta, Apache uima-as prior to 2.10.2, Apache uimaFIT prior to 2.4.0, Apache ui… Uimaj 2.2.2 / 2.4.0+ Fix from $1,6002018-04-26 HIGH 8.1 CVE-2018-1335EPSS 94% From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the com… Tika 1.18+ Fix from $1,9502018-04-25 MEDIUM 5.5 CVE-2018-1338 A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18. Tika 1.18+ Fix from $1,6002018-04-25 MEDIUM 5.5 CVE-2018-1339 A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18. Tika 1.18+ Fix from $1,6002018-04-25 CRITICAL 9.8 CVE-2018-1290 In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL para… Fineract Mitigation only Fix from $2,3002018-04-20 HIGH 8.8 CVE-2018-1289 In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain… Fineract Mitigation only Fix from $1,9502018-04-20 HIGH 8.1 CVE-2018-1291 Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entities with … Fineract Mitigation only Fix from $1,9502018-04-20 HIGH 8.1 CVE-2018-1292 Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/u… Fineract Mitigation only Fix from $1,9502018-04-20 HIGH 7.5 CVE-2018-1308EPSS 21% This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` … Solr after 7.2.1 Fix from $1,9502018-04-09 CRITICAL 9.1 CVE-2018-1282EPSS 6% This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup th… Hive after 2.3.2 Fix from $2,3002018-04-05 CRITICAL 9.8 CVE-2018-1295EPSS 6% In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes i… Ignite after 2.3.0 Fix from $2,3002018-04-02 HIGH 7.5 CVE-2018-1327EPSS 9% The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with special… Struts after 2.5.14.1 Fix from $1,9502018-03-27 CRITICAL 9.8 CVE-2018-1312EPSS 16% In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly g… HTTP Server Mitigation only Fix from $2,3002018-03-26 HIGH 8.1 CVE-2017-15715EPSS 86% In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than… HTTP Server after 2.4.29 Fix from $1,9502018-03-26 HIGH 7.5 CVE-2017-15710EPSS 18% In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-La… HTTP Server No fix yet Fix from $1,9502018-03-26 HIGH 7.5 CVE-2018-1303EPSS 70% A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing… HTTP Server after 2.4.29 Fix from $1,9502018-03-26 MEDIUM 5.9 CVE-2018-1301EPSS 15% A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is re… HTTP Server after 2.4.29 Fix from $1,6002018-03-26 MEDIUM 5.9 CVE-2018-1302EPSS 13% When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially… HTTP Server after 2.4.29 Fix from $1,6002018-03-26 MEDIUM 5.3 CVE-2018-1283EPSS 10% In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a r… HTTP Server after 2.4.29 Fix from $1,6002018-03-26 HIGH 7.5 CVE-2018-1294 If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and that input co… Commons Email after 1.4 Fix from $1,9502018-03-20 HIGH 7.2 CVE-2018-1321EPSS 18% An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and … Syncope 1.2.11 / 2.0.8+ Fix from $1,9502018-03-20 MEDIUM 5.5 CVE-2018-1324 A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and Z… Commons Compress after 8.0.27 Fix from $1,6002018-03-16 MEDIUM 6.1 CVE-2018-1319 In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted… Allura after 1.8.0 Fix from $1,6002018-03-15 HIGH 7.5 CVE-2018-1323EPSS 46% The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-… Tomcat Jk Connector after 1.2.42 Fix from $1,9502018-03-12 HIGH 7.5 CVE-2017-12174EPSS 6% It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when rec… Artemis 2.4.0+ Fix from $1,9502018-03-07