Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2018-1316 The ODE process deployment web service was sensible to deployment messages with forged names. Using a path for the name was allowing directory traver… Ode after 1.3.2 Fix from $1,9502018-03-05 CRITICAL 9.8 CVE-2017-12627EPSS 8% In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain condition… Xerces C\+\+ 3.2.1+ Fix from $2,3002018-03-01 MEDIUM 5.9 CVE-2018-1304EPSS 17% The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 t… Tomcat after 9.0.4 Fix from $1,6002018-02-28 MEDIUM 6.5 CVE-2018-1286 In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny servi… Openmeetings after 4.0.1 Fix from $1,6002018-02-28 HIGH 8.6 CVE-2017-5660 There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issu… Traffic Server after 6.2.0 Fix from $1,9502018-02-27 HIGH 7.5 CVE-2017-7671 There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can c… Traffic Server after 6.2.0 Fix from $1,9502018-02-27 MEDIUM 6.1 CVE-2012-3536 Two XSS vulnerabilities were fixed in message list and view in the Hupa Webmail application from the Apache James project. An attacker could send a c… Hupa 0.0.3+ Fix from $1,6002018-02-27 CRITICAL 9.8 CVE-2017-15692 In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains acce… Geode 1.4.0+ Fix from $2,3002018-02-27 HIGH 7.5 CVE-2017-15693 In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause t… Geode 1.4.0+ Fix from $1,9502018-02-27 HIGH 7.5 CVE-2017-15696 When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration req… Geode after 1.3.0 Fix from $1,9502018-02-26 MEDIUM 6.5 CVE-2018-1305EPSS 14% Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 … Tomcat after 8.5.27 Fix from $1,6002018-02-23 HIGH 8.8 CVE-2013-0267 The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated user… Vcl 2.3.2+ Fix from $1,9502018-02-21 MEDIUM 6.5 CVE-2015-0203EPSS 9% The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via an AMQP message wi… Qpid after 0.30 Fix from $1,6002018-02-21 MEDIUM 6.5 CVE-2009-4267 The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof log entries via the numRows p… Juddi Mitigation only Fix from $1,6002018-02-19 MEDIUM 6.5 CVE-2016-8750EPSS 5% Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly a… Karaf 4.0.8+ Fix from $1,6002018-02-19 MEDIUM 6.5 CVE-2017-15712 Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malici… Oozie Mitigation only Fix from $1,6002018-02-19 CRITICAL 9.8 CVE-2018-1287 In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an at… Jmeter Mitigation only Fix from $2,3002018-02-14 MEDIUM 6.5 CVE-2017-15699 A Denial of Service vulnerability was found in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0. To exploit this vulnerability, a remote user mus… Qpid Dispatch Patch available Fix from $1,6002018-02-13 CRITICAL 9.8 CVE-2018-1297EPSS 10% When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access … Jmeter Mitigation only Fix from $2,3002018-02-13 HIGH 8.8 CVE-2016-5397EPSS 7% The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affe… Thrift after 0.9.3 Fix from $1,9502018-02-12 HIGH 7.8 CVE-2016-8742 The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file p… Couchdb No fix yet Fix from $1,9502018-02-12 HIGH 8.1 CVE-2018-1307 In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data… Juddi after 3.3.4 Fix from $1,9502018-02-09 MEDIUM 5.9 CVE-2018-1298 A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocols 0-8, … Qpid Broker J Mitigation only Fix from $1,6002018-02-09 HIGH 7.5 CVE-2018-1299 In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application. Some webservers used with A… Allura 1.8.0+ Fix from $1,9502018-02-06 CRITICAL 9.8 CVE-2016-6813EPSS 6% Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is a… Cloudstack after 4.8.1.0 Fix from $2,3002018-02-06 HIGH 7.4 CVE-2017-3160 After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, the scripts will fetch Gradle o… Cordova 6.1.2+ Fix from $1,9502018-02-01 MEDIUM 5.9 CVE-2017-15698 When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly h… Tomcat Native after 1.2.14 Fix from $1,6002018-01-31 MEDIUM 5.3 CVE-2017-15706EPSS 6% As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 inc… Tomcat after 8.5.23 Fix from $1,6002018-01-31 HIGH 7.5 CVE-2017-12626EPSS 10% Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and m… Poi 3.17+ Fix from $1,9502018-01-29 MEDIUM 5.0 CVE-2017-15703 Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a den… Nifi after 1.4.0 Fix from $1,6002018-01-25