Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2017-7684 Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded. An attacker can cause a denial of service by uploading multiple large files… Openmeetings Mitigation only Fix from $1,9502017-07-17 MEDIUM 6.1 CVE-2017-7663 Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0. Openmeetings Mitigation only Fix from $1,6002017-07-17 CRITICAL 9.1 CVE-2016-6793EPSS 8% The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop… Wicket 1.5.17 / 6.25.0+ Fix from $2,3002017-07-17 HIGH 7.2 CVE-2015-0249 The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary… Roller Mitigation only Fix from $1,9502017-07-17 CRITICAL 9.1 CVE-2017-9788EPSS 57% In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or… HTTP Server after 2.4.26 Fix from $2,3002017-07-13 HIGH 7.5 CVE-2017-9789EPSS 10% When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, r… HTTP Server Mitigation only Fix from $1,9502017-07-13 HIGH 7.5 CVE-2017-9787EPSS 11% When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts versio… Struts Mitigation only Fix from $1,9502017-07-13 MEDIUM 5.9 CVE-2017-7672EPSS 10% If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used t… Struts Mitigation only Fix from $1,6002017-07-13 MEDIUM 6.1 CVE-2017-7678 In Apache Spark before 2.2.0, it is possible for an attacker to take advantage of a user's trust in the server to trick them into visiting a link tha… Spark after 2.1.1 Fix from $1,6002017-07-12 CRITICAL 9.8 CVE-2017-5640 It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to ski… Impala Mitigation only Fix from $2,3002017-07-10 HIGH 7.5 CVE-2017-5652 During a routine security analysis, it was found that one of the ports in Apache Impala (incubating) 2.7.0 to 2.8.0 sent data in plaintext even when … Impala Mitigation only Fix from $1,9502017-07-10 HIGH 7.5 CVE-2017-7670 The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TCP connec… Traffic Control after 1.8.0 Fix from $1,9502017-07-10 CRITICAL 9.8 CVE-2017-9791 KEVEPSS 99% The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the Act… Struts Patch available Fix from $2,3002017-07-10 HIGH 7.5 CVE-2017-7660EPSS 6% Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node… Solr Mitigation only Fix from $1,9502017-07-07 HIGH 7.5 CVE-2017-7686 Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality… Ignite Mitigation only Fix from $1,9502017-06-28 CRITICAL 9.8 CVE-2017-3167EPSS 20% In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication p… HTTP Server 2.2.33 / 2.4.26+ Fix from $2,3002017-06-20 CRITICAL 9.8 CVE-2017-3169EPSS 20% In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_con… HTTP Server Mitigation only Fix from $2,3002017-06-20 CRITICAL 9.8 CVE-2017-7679EPSS 39% In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Typ… HTTP Server 2.2.33 / 2.4.26+ Fix from $2,3002017-06-20 HIGH 7.5 CVE-2017-7668EPSS 57% The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to searc… HTTP Server Patch available Fix from $1,9502017-06-20 MEDIUM 6.5 CVE-2015-3254EPSS 5% The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vecto… Thrift after 0.9.2 Fix from $1,6002017-06-16 CRITICAL 9.8 CVE-2017-7676 Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in u… Ranger after 0.7.0 Fix from $2,3002017-06-14 MEDIUM 5.9 CVE-2016-8746 Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion fla… Ranger after 0.6.2 Fix from $1,6002017-06-14 MEDIUM 5.9 CVE-2017-7677 In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for creat… Ranger after 0.7.0 Fix from $1,6002017-06-14 HIGH 7.5 CVE-2017-7667 Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin. Nifi after 0.7.3 Fix from $1,9502017-06-12 MEDIUM 6.1 CVE-2017-7665 In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS iss… Nifi after 0.7.3 Fix from $1,6002017-06-12 HIGH 7.5 CVE-2015-5175EPSS 11% Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service. Cxf Fediz after 1.1.2 Fix from $1,9502017-06-07 MEDIUM 6.5 CVE-2016-5004EPSS 6% The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource … Ws Xmlrpc No fix yet Fix from $1,6002017-06-06 HIGH 7.5 CVE-2017-5664EPSS 17% The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is configured for the error that occ… Tomcat Mitigation only Fix from $1,9502017-06-06 HIGH 7.5 CVE-2017-7669 In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. W… Hadoop Mitigation only Fix from $1,9502017-06-05 HIGH 7.5 CVE-2016-3083 Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the server's … Hive Mitigation only Fix from $1,9502017-05-30