Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.8 CVE-2017-5646 For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing … Knox Mitigation only Fix from $1,6002017-05-26 HIGH 8.0 CVE-2017-5657 Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the … Archiva after 2.2.1 Fix from $1,9502017-05-22 MEDIUM 6.1 CVE-2015-5241 After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect… Juddi Mitigation only Fix from $1,6002017-05-19 HIGH 8.8 CVE-2017-7661 Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) sty… Cxf Fediz after 1.4.0 Fix from $1,9502017-05-16 HIGH 8.8 CVE-2017-7662 Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application that allows c… Cxf Fediz after 1.3.2 Fix from $1,9502017-05-16 HIGH 7.5 CVE-2016-8741EPSS 6% The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices… Qpid Broker J Mitigation only Fix from $1,9502017-05-15 MEDIUM 6.5 CVE-2017-5655 In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary file… Ambari Mitigation only Fix from $1,6002017-05-15 HIGH 7.5 CVE-2017-5654 In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on … Ambari Mitigation only Fix from $1,9502017-05-12 HIGH 7.5 CVE-2016-6799 Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d()… Cordova after 5.2.2 Fix from $1,9502017-05-09 MEDIUM 5.9 CVE-2016-4467 The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname m… Qpid Proton Mitigation only Fix from $1,6002017-05-02 HIGH 7.3 CVE-2017-3162EPSS 6% HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query parameter that is not validate… Hadoop after 2.6.5 Fix from $1,9502017-04-26 MEDIUM 6.1 CVE-2017-3161 The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter. Hadoop after 2.6.5 Fix from $1,6002017-04-26 HIGH 7.5 CVE-2017-5656EPSS 7% Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an a… Cxf 3.0.13 / 3.1.11+ Fix from $1,9502017-04-18 MEDIUM 5.3 CVE-2017-5653EPSS 11% JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which… Cxf after 3.1.11 Fix from $1,6002017-04-18 HIGH 7.3 CVE-2017-5661 In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciously formed S… Formatting Objects Processor after 2.1 Fix from $1,9502017-04-18 HIGH 7.3 CVE-2017-5662 In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously form… Batik after 1.8 Fix from $1,9502017-04-18 CRITICAL 9.8 CVE-2017-5645EPSS 90% In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a … Log4j 2.8.2+ Fix from $2,3002017-04-17 HIGH 7.5 CVE-2016-5396 Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack. Traffic Server Patch available Fix from $1,9502017-04-17 HIGH 7.5 CVE-2017-5659 Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding. Traffic Server after 6.2.0 Fix from $1,9502017-04-17 CRITICAL 9.8 CVE-2017-5651EPSS 8% In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processin… Tomcat Patch available Fix from $2,3002017-04-17 CRITICAL 9.1 CVE-2017-5648EPSS 13% While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0… Tomcat Mitigation only Fix from $2,3002017-04-17 HIGH 7.5 CVE-2017-5647EPSS 17% A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.… Tomcat Mitigation only Fix from $1,9502017-04-17 HIGH 7.5 CVE-2017-5650EPSS 8% In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated … Tomcat Mitigation only Fix from $1,9502017-04-17 CRITICAL 9.8 CVE-2016-6808EPSS 19% Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42. Tomcat Jk Connector 1.2.42+ Fix from $2,3002017-04-12 CRITICAL 9.8 CVE-2016-0779EPSS 10% The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted s… Tomee after 1.7.3 Fix from $2,3002017-04-11 HIGH 8.8 CVE-2016-6811 In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Hadoop after 2.7.3 Fix from $1,9502017-04-11 MEDIUM 5.9 CVE-2016-6805 Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents. Ignite after 1.8 Fix from $1,6002017-04-07 CRITICAL 9.8 CVE-2016-6809EPSS 8% Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to d… Nutch after 1.13 Fix from $2,3002017-04-06 CRITICAL 9.8 CVE-2016-8735 KEVEPSS 90% Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M1… Tomcat 6.0.48 / 7.0.73+ Fix from $2,3002017-04-06 HIGH 7.5 CVE-2017-5649 Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUST… Geode after 1.1.0 Fix from $1,9502017-04-04