Vulnerability index

Browse CVEs

2,864 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 9.3 CVE-2014-3524EPSS 15% Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc sp… Openoffice 4.1.1 / 4.2.6+ Fix from $1,9502014-08-26 HIGH 10.0 CVE-2014-3525 Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors,… Traffic Server No fix yet Fix from $1,9502014-08-22 MEDIUM 5.8 CVE-2014-3577EPSS 9% org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify … Httpclient after 4.3.4 Fix from $1,6002014-08-21 MEDIUM 5.0 CVE-2014-3523EPSS 16% Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x before 2.4.10 on Windows, when … HTTP Server Patch available Fix from $1,6002014-07-20 MEDIUM 6.8 CVE-2014-0226EPSS 86% Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buff… HTTP Server 2.2.29 / 2.4.10+ Fix from $1,6002014-07-20 MEDIUM 5.0 CVE-2014-0231EPSS 44% The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of ser… HTTP Server 2.2.29 / 2.4.10+ Fix from $1,6002014-07-20 MEDIUM 5.0 CVE-2014-3503EPSS 6% Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via… Syncope No fix yet Fix from $1,6002014-07-11 MEDIUM 5.0 CVE-2011-4367EPSS 33% Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allo… Myfaces after 2.1.5 Fix from $1,6002014-06-19 MEDIUM 5.0 CVE-2014-0075EPSS 20% Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6.0.40, 7.… Tomcat Mitigation only Fix from $1,6002014-05-31 MEDIUM 5.0 CVE-2014-0095EPSS 8% java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread c… Tomcat Patch available Fix from $1,6002014-05-31 MEDIUM 5.0 CVE-2013-2758EPSS 6% Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable se… Cloudstack Patch available Fix from $1,6002014-05-23 MEDIUM 5.0 CVE-2013-2756EPSS 6% Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypa… Cloudstack Patch available Fix from $1,6002014-05-23 MEDIUM 6.8 CVE-2012-5649EPSS 7% Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to execute arbitrary code via a JSONP callback, relat… Couchdb after 1.0.3 Fix from $1,6002014-05-23 MEDIUM 5.8 CVE-2014-0116EPSS 7% CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass me… Struts Mitigation only Fix from $1,6002014-05-08 HIGH 7.5 CVE-2014-0114EPSS 96% Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commo… Commons Beanutils after 1.9.1 Fix from $1,9502014-04-30 MEDIUM 5.0 CVE-2013-7372 The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/crypto/SHA1PRNG_SecureRandomImpl.… Harmony after 6.0 Fix from $1,6002014-04-29 HIGH 7.5 CVE-2014-0112EPSS 98% ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "mani… Struts 2.3.16.2+ Fix from $1,9502014-04-29 HIGH 7.5 CVE-2014-0113EPSS 78% CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method… Struts 2.3.16.2+ Fix from $1,9502014-04-29 MEDIUM 6.5 CVE-2014-0111 Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Co… Syncope 1.0.9 / 1.1.7+ Fix from $1,6002014-04-17 HIGH 7.5 CVE-2014-0107EPSS 14% The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is en… Xalan Java after 2.7.1 Fix from $1,9502014-04-15 MEDIUM 5.0 CVE-2013-5704EPSS 60% The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the… HTTP Server Patch available Fix from $1,6002014-04-15 HIGH 7.5 CVE-2014-0050EPSS 83% MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to c… Commons Fileupload after 1.3 Fix from $1,9502014-04-01 MEDIUM 5.0 CVE-2014-2668EPSS 22% Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via the count parameter to /_uuids. Couchdb after 1.5.0 Fix from $1,6002014-03-28 HIGH 7.5 CVE-2014-0002EPSS 33% The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other uns… Camel after 2.11.3 Fix from $1,9502014-03-21 HIGH 7.5 CVE-2014-0003EPSS 7% The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbit… Camel after 2.11.3 Fix from $1,9502014-03-21 MEDIUM 5.0 CVE-2012-5641EPSS 9% Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1… Couchdb after 2.3.2 Fix from $1,6002014-03-18 MEDIUM 5.0 CVE-2013-6438EPSS 27% The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace charac… HTTP Server 2.2.27 / 2.4.9+ Fix from $1,6002014-03-18 MEDIUM 5.0 CVE-2014-0098EPSS 26% The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a de… HTTP Server 2.2.27 / 2.4.9+ Fix from $1,6002014-03-18 MEDIUM 5.0 CVE-2014-0094EPSS 100% The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is … Struts 2.3.16.1+ Fix from $1,6002014-03-11 HIGH 7.5 CVE-2012-6637EPSS 9% Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote a… Cordova after 3.3.0 Fix from $1,9502014-03-03